Impact
The kernel component cxlctl_set_feature() allocates an output buffer based on a user‑supplied size but fails to verify that the buffer is large enough to hold the required response header. When the size is zero the allocator returns a zero‑length pointer that passes a null check, after which the code writes into that pointer, causing a null‑pointer dereference and a kernel panic. This constitutes a local denial of service at the kernel level.
Affected Systems
All Linux kernel implementations that include the unpatched cxl/features module are affected. No specific kernel version range is provided in the advisory; the vulnerability exists until the patch that introduces the output‑buffer size check is applied.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low expected exploitation probability. Based on the description, it is inferred that the attack vector is local, requiring access to the cxlctl interface and local user privileges; remote exploitation would be unlikely without additional privilege escalation. The severity is primarily to availability, as the flaw results in a kernel crash.
OpenCVE Enrichment