Impact
The vulnerability stems from an infinite loop in the Linux kernel’s CXL poison scan routine. A device that repeatedly reports a payload count of zero while setting the CXL_POISON_FLAG_MORE flag causes the loop to never advance the record counter, never reach the maximum error guard, and hold the poison mutex indefinitely. This lock remains inside the sysfs-triggered scan thread, blocking all subsequent poison operations on the device and effectively hanging the related subsystem.
Affected Systems
Any Linux distribution that includes the CXL mailbox (cxl/mbox) component of the kernel is potentially affected. The vendor name is Linux and the product is the Linux kernel; specific version information is not provided in the advisories.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low probability of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, and no CVSS score is supplied. Based on the description, an attacker would need to interact with a CXL device that can return the anomalous payload; this could occur locally or via a compromised device. The impact is a denial of service through a hung scan thread and blocked poison operations. No known workaround is specified.
OpenCVE Enrichment
Debian DLA
Debian DSA