Impact
The vulnerability arises because the asus_wireless platform driver accepts a probe request even when no matching ACPI device is found. This leaves the driver in a partially initialized state with a NULL companion pointer. When the driver later attempts to remove the device, it dereferences this NULL pointer, causing a kernel crash. The crash could be triggered locally by an attacker who can force the driver to bind to a device without a proper ACPI companion, providing a vector for denial of service. The weakness is a classic null pointer dereference, making control of driver loading a critical concern.
Affected Systems
The defect is present in the Linux kernel’s ASUS wireless platform driver on x86 architectures. No specific kernel version range is listed, but any kernel that includes the unpatched asus_wireless driver is affected. The vulnerability applies to any system running a platform driver that uses the force-bind mechanism without verifying the presence of a matching ACPI companion.
Risk and Exploitability
The CVSS metric is not provided, but a NULL pointer dereference that can crash the kernel is considered high severity. The EPSS score is below 1 %, indicating a very low predicted exploitation probability at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local driver load or a forced binding operation performed by a user with sufficient privileges to load kernel modules. An attacker could trigger the fault by binding the asus_wireless driver to a device without an ACPI companion, leading to a kernel panic and system disruption.
OpenCVE Enrichment