Impact
The kernel driver for Qualcomm qcom_q6v5_adsp fails to decrement the reference count on a device node after parsing its properties. The resulting reference leak can cause the device node to remain in memory indefinitely, eventually exhausting kernel resources and potentially leading to a denial‑of‑service state. The vulnerability is a classic reference‑counting error that can grow unbounded per invocation of the affected function.
Affected Systems
Any Linux kernel running the remoteproc driver for the Qualcomm qcom_q6v5_adsp module is affected. The issue exists in versions of the kernel prior to the patch that adds a call to of_node_put() in adsp_map_carveout. Because the vendor list is simply "Linux:Linux", the risk applies to all distributions that include the unpatched kernel.
Risk and Exploitability
The EPSS score is reported as less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation. However, an attacker with the ability to invoke the affected function repeatedly—such as a privileged user or a malicious kernel module—could expedite resource exhaustion. The attack vector is local to the kernel, requiring code that can trigger the reference leak through the remoteproc interface.
OpenCVE Enrichment
Debian DLA
Debian DSA