Impact
The Linux kernel contains a flaw in the RISC‑V ACPI driver where a call to acpi_get_handle() can fail, but its return value is not checked. This oversight leaves the variable link_handle uninitialized, and subsequent use of that uninitialized pointer can cause the kernel to crash or behave unpredictably. The weakness is a classic instance of an uninitialized variable (CWE‑758). The resulting system instability manifests as a denial‑of‑service condition since the kernel may panic and halt the system.
Affected Systems
The affected product is the Linux operating system. All builds of the Linux kernel that include the RISC‑V ACPI subsystem prior to the commit that added a status check on acpi_get_handle() are vulnerable. No specific version numbers are supplied in the advisory, so any kernel not yet updated with the fix is considered impacted.
Risk and Exploitability
The CVSS metric is not provided, but the EPSS score indicates an extremely low probability of exploitation—less than 1%. The vulnerability is not listed in CISA’s KEV catalog, and no public exploits are known. Because the flaw requires interaction with ACPI device code, the most likely attack vector is a local privileged user who can trigger ACPI evaluation. While the potential impact is severe (kernel crash), the combination of low EPSS and lack of published exploits suggests a moderate overall risk if the system remains on an unpatched kernel.
OpenCVE Enrichment
Debian DLA
Debian DSA