Impact
The vulnerability arises when the ARM SCMI transport registers mailbox or SMC interrupts before the associated channel state is fully published. During this race window a pending or spurious callback can be delivered, causing the receive path to dereference a NULL transport information pointer. The result is an unpredictable kernel failure, typically manifesting as a crash or oops. This denial‑of‑service effect could be exploited by an attacker with kernel or privileged process access to trigger the early callbacks and bring the system down.
Affected Systems
The issue exists in the Linux kernel wherever the ARM SCMI mailbox or SMC transport code is compiled. The known affected products list only the Linux kernel; specific version information is not provided. Consequently any kernel built with the arm_scmi transport that contains the code path described may be vulnerable until the upstream fix is applied.
Risk and Exploitability
The EPSS score is under 1 % indicating a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Because the fault occurs inside kernel space and requires privileged context to trigger the early callback, the attack surface is limited. However, once triggered the impact is catastrophic for uptime. Based on the raw CVSS score (not supplied) and the nature of a NULL pointer dereference, the severity is high, but the exploitation likelihood remains low without an active local vector.
OpenCVE Enrichment
Debian DLA
Debian DSA