Impact
In the Linux kernel's bcm_vk driver, the synchronization around the message queue initialization flag, msgq_inited, was implemented using atomic_set/atomic_read without proper acquire/release ordering. As a result, the flag can be set before the queue structure is fully populated, allowing readers to observe an initialized flag while still accessing stale or incomplete data. This race condition can lead to unpredictable behavior, data corruption, or incorrect driver operation, potentially creating a kernel state that an attacker might exploit to gain elevated privileges or cause a denial of service. The flaw is a classic concurrency issue related to improper initialization.
Affected Systems
This vulnerability affects any Linux system that builds and loads the bcm_vk driver within the kernel. No specific version bounds are provided, so all current and past kernel releases that compile this driver are potentially impacted. Vendors include Linux distributions that ship this driver as part of the kernel package. Because the kernel is the target, all machines running a kernel that is not patched by the referenced commit are susceptible.
Risk and Exploitability
The CVSS score is not specified, and the EPSS score is less than 1%, indicating a very low probability of exploitation at this time. The vulnerability is listed as not present in CISA’s KEV catalog. Exploitation would likely require local or elevated access to a system running the affected kernel configuration, and the exploitation surface is limited to scenarios that involve both the writer and reader of the bcm_vk message queue. Given the low prevalence and narrow attack surface, the risk remains moderate but not negligible. Monitoring for kernel updates and applying the patch is strongly recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA