Impact
The Linux kernel function that destroys a rpmsg endpoint during driver detach now deadlocks because the endpoint destroy routine attempts to unregister the rpmsg device while the device mutex is already held higher up in the call chain. This recursive lock acquisition causes the module removal to hang indefinitely, effectively freezing the system until a reboot. The vulnerability does not compromise confidentiality or integrity; it merely disrupts availability.
Affected Systems
Any Linux system deploying the rpmsg and GLINK drivers that has not incorporated the patch may be affected. The advisory does not specify a particular kernel version, so all distributions shipping an unpatched kernel are potentially impacted. Devices that rely on Qualcomm Glink interfaces are explicitly mentioned as common victims because the code paths for rpmsg teardown are exercised there.
Risk and Exploitability
The EPSS score indicates an exploitation probability lower than 1% and the vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is local: an attacker with privileged or local access who can unload the rpmsg module (for example via rmmod or maintenance scripts) could intentionally trigger the deadlock. The condition required is the ability to unload the module; the consequence is a kernel stall that requires a reboot to recover, resulting in a denial‑of‑service. No remote exploitation is possible, and confidentiality or integrity are unaffected.
OpenCVE Enrichment
Debian DLA
Debian DSA