Impact
The ad525x_dpot driver creates device‑specific sysfs files during probe but relies on the caller to roll back those files if probe fails, and it leaves the removal routine to match every file it created; this design permits inconsistent kernel state when a probe fails or a device is removed, potentially leaving stale sysfs entries that can lead to kernel crashes or instability when accessed.
Affected Systems
All Linux kernel installations that load the ad525x_dpot device driver are potentially vulnerable; no specific kernel version range is specified in the advisory, so any kernel that has not incorporated the committed changes that move the device attributes into driver core dev_groups remains exposed.
Risk and Exploitability
The EPSS score is below 1 percent and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild, but it requires local access to load or probe the driver; the likely attack vector is a local attacker triggering a probe or removal that leaves inconsistent sysfs state, which may cause denial of service or kernel instability.
OpenCVE Enrichment
Debian DLA
Debian DSA