Impact
The Linux kernel has a flaw in the drm/msm module where the recover_worker function increments a task reference count via get_pid_task() but fails to release it in the else branch, causing a reference leak for every GPU hang recovery. This leak results in unchecked kernel memory consumption, potentially exhausting system resources and degrading kernel stability. The weakness is a classic Resource Management Flaw and can lead to a denial of service if numerous GPU hang recoveries occur.
Affected Systems
All Linux kernel installations that include the drm/msm driver and have not applied the fix referenced in the patch repo. The vulnerability is present in the mainline kernel and any derivative kernels that have not integrated the commit that added the missing put_task_struct() call. No explicit version numbers are supplied, so any kernel build from sources that predates the fix is affected.
Risk and Exploitability
The EPSS score is reported as less than 1%, indicating a very low probability of exploitation. The vulnerability is not included in the CISA KEV catalog, and no CVSS score is provided; however, the potential for resource exhaustion suggests a high impact if triggered repeatedly. The attack vector likely requires repeated GPU hang events to accumulate the leaks, implying a localized or system‑level DoS rather than immediate remote code execution. Because the exploit requires the kernel to be in a state where GPU hangs occur, operational circumstances and denial of service are the primary concerns.
OpenCVE Enrichment