Impact
A bug was introduced in the Linux kernel when sync_state support was added to the clk and pmdomain subsystems. The issue manifests as a warning when unused CAMCC_GDSC_CLK clocks are shut down, with the guard status remaining stuck at "on" while the system continues to run. The warning message does not cause an immediate crash, but it signals that the power‑gating state machine is not progressing as intended, which could lead to resource leakage or a subtle degradation in power management behavior. No exploitation route is described in the provided data, and the impact appears limited to a disruptive runtime notification rather than direct control compromise.
Affected Systems
All Linux kernel builds exist the same source path, including the default distributions that ship the kernel version 7.1.0+ or newer. Because the affected string references a generic Linux kernel, the vulnerability could affect any kernel that includes the camcc-sc8280xp driver without an applied fix. The precise version range that is corrected is not listed in the data, so administrators must check the kernel changelog for the camcc‑sc8280xp driver in the tree that matches their distribution.
Risk and Exploitability
The EPSS score is less than 1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, which further suggests it is not currently being actively exploited in the wild. Attack surface is internal to the kernel’s clock control subsystem; no user‑space or network‑based vectors are described. Given the nature of the fault—a warning due to an internal state inconsistency—there is no demonstrated capability for denial of service, privilege escalation, or other security‑critical effects. The risk remains primarily in potential reliability impact rather than direct security breach.
OpenCVE Enrichment
Debian DLA
Debian DSA