Impact
The Linux kernel for RISC‑V contains a loop in riscv_acpi_add_prt_dep() that mishandles error conditions by continuing the loop without advancing the entry pointer. This logic flaw likely leads to incorrect ACPI table parsing and could cause kernel stalls or misconfigured devices. The description does not state that the flaw allows arbitrary memory read or write; it appears to affect only parsing logic, so the primary consequence is service disruption rather than privilege escalation.
Affected Systems
Linux kernel builds compiled for the RISC‑V architecture that include the original loop implementation are affected. The fix appears in the referenced commits, so any kernel version prior to those patches is vulnerable. Specific kernel release numbers are not provided, but the issue exists in all builds that have not yet incorporated the corrections.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation in the wild. Based on the description, an attacker would need to supply or influence ACPI tables processed during boot or device enumeration, a scenario that generally requires privileged or local access. If such a table is crafted, denial of service or incorrect configuration is possible, but overall risk is modest because the flaw does not provide direct arbitrary memory access or privilege elevation.
OpenCVE Enrichment
Debian DLA
Debian DSA