Impact
This kernel flaw allows concurrent Get/Set Feature operations on the same CXL mailbox to interleave, bypassing the mailbox mutex protection and converting a single mailbox command into several split commands. The resulting race condition corrupts the device's transfer context, which can lead to incorrect device state or failure of subsequent operations. An attacker who can trigger overlapping transfers—such as a privileged local user or a compromised driver—could exploit this issue to cause device misbehavior or a denial‑of‑service condition.
Affected Systems
All Linux kernels that include the cxl/features subsystem, including the mainstream distributions, are affected until the per‑mailbox feat_mutex patch is applied. The vulnerability is intentionally present in any kernel that contains the cxl driver, as the CPE identifies all Linux kernel releases.
Risk and Exploitability
The EPSS score of less than 1% suggests a very low overall probability of exploitation in the general population. The vulnerability is not listed in the CISA KEV catalog, but its impact on device integrity makes it a serious risk if an attacker has sufficient local privileges or can run code with kernel or driver‑level access. Exploitation requires concurrent CXL operations on the same mailbox, which is feasible only when the kernel is running normally and the driver is active.
OpenCVE Enrichment