Impact
The asus_wmi driver in the Linux kernel fails to clean up previously allocated resources when initialization errors occur. The issue involves multiple subsystems such as input devices, sysfs groups, backlights, rfkill, and screenpad devices. Because the error handling labels are out of order, cleanup for earlier registrations is bypassed, leaking kernel memory and device handles. Although the immediate impact is not code execution, repeated failures can exhaust limited kernel resources, potentially leading to a denial of service or weakening system stability.
Affected Systems
Any Linux kernel build that includes the unpatched Asus WMI driver is affected, including mainstream distributions that ship the kernel with asus_wmi. The specific kernel versions are not enumerated in the data, so a vendor’s default kernel may be impacted if it contains the original driver code prior to the fix.
Risk and Exploitability
The CVSS score of 7 denotes high severity, while the EPSS score of less than 1 % indicates a low probability of exploitation at present. Based on the description, it is inferred that an attacker would need local access to trigger a probe failure during driver initialization, for example by manipulating device attachment or kernel loading procedures. The risk is principally resource exhaustion, which could degrade system availability if an attacker causes repeated failures. The vulnerability is not listed in CISA’s KEV catalog, suggesting no public exploits have been observed.
OpenCVE Enrichment