Impact
The vulnerability in the Linux kernel’s aspeed_udc driver allows a failed DMA buffer allocation to be dereferenced during device probe, leading to a null pointer dereference that crashes the kernel. This results in a denial of service because the operating system becomes unstable or stops responding. The weakness is a classic unchecked return value error that can corrupt kernel memory, potentially preventing normal system operation. The impact is limited to the system hosting the affected kernel; an attacker would need to control or connect to the USB device to trigger the crash.
Affected Systems
All Linux kernel deployments that include the Aspeed Universal Device Controller (UDC) driver, particularly on boards using Aspeed hardware, are affected. The issue exists in kernel versions running the unpatched aspeed_udc code, which prior to the 6.16 mainline update contained the bug. End‑users running older kernels without the fix should consider updating the kernel or removing the driver if the USB gadget functionality is not required.
Risk and Exploitability
The EPSS score is below 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector would be local and would require physical or direct USB access to the affected device to trigger the fault. No public exploit is known, and the risk is largely mitigated by the low exploitation probability and the necessity of a direct device connection.
OpenCVE Enrichment
Debian DLA
Debian DSA