Impact
A null pointer dereference in the Mellanox platform driver for the PMC module causes a kernel oops when the driver is bound to a device that lacks an ACPI companion object. The code passes the companion pointer to a helper that dereferences it without checking for null. When an attacker forces the driver onto such a device, the kernel crashes, resulting in a system reboot or loss of service. The vulnerability does not provide direct remote code execution or privilege escalation, but it can interrupt critical workloads. The weakness is a classic null pointer dereference (CWE‑476).
Affected Systems
All Linux kernel builds that include the unpatched mlxbf‑pmc driver are affected. The driver is part of the official kernel source tree, so any distribution that ships a kernel containing this driver before the fix is potentially vulnerable. No specific kernel version range is listed, so every kernel revision that has the bug is at risk.
Risk and Exploitability
The EPSS score indicates a very low likelihood of exploitation in the wild (<1 %). The vulnerability is not listed in the CISA KEV catalog. Attackers would need to force the driver onto a device that does not provide an ACPI companion, which typically requires local privilege or the ability to invoke device_match_driver_override(). This vector is inferred from the description: the patch notes mention forced binding as the trigger. With local root privileges the exploit is trivial; without such access, exploitation is unlikely. Overall risk is moderate due to the low exploitation probability but high impact upon successful exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA