Impact
The Linux kernel contains a bug in the LED subsystem for LG laptop platform devices where a callback may attempt to access the kbd_backlight LED device even when it has not been successfully registered. During hardware removal, the code also unconditionally unregisters LED devices that may not exist. If the driver accesses an unregistered device, it can dereference a null or stale pointer, causing a kernel crash and potentially a system reboot. This bug does not provide an information disclosure or code execution pathway, but it can terminate the kernel, leading to service interruption.
Affected Systems
The vulnerability affects all Linux kernel builds that include the LG laptop platform drivers before the commit that introduces the fix. Since the issue is tied to the generic kernel, it applies to all distributions running a vulnerable kernel version, regardless of vendor or OS edition. Users of stock kernel images or custom builds that have not applied the patch are impacted.
Risk and Exploitability
The CVSS score is not supplied, but the EPSS score is listed as < 1%, indicating a very low probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires an attacker to trigger a hardware event that causes the faulty callback, which is unlikely in ordinary operation. Consequently, the overall risk has been deemed low, though the impact would be severe if triggered.
OpenCVE Enrichment
Debian DLA
Debian DSA