Impact
The Linux kernel contains a flaw in the MHI device creation routine where a reference counter is leaked when an error occurs during device initialization. Normally the error path releases only one of two device references, allowing the device and its associated channels to remain in memory even though the device was never registered. This leak can accumulate and lead to resource exhaustion, potentially destabilizing the kernel or causing a denial of service. The vulnerability is rooted in improper reference count handling, a classic cases of resource management weakness.
Affected Systems
Linux kernel users. The issue may affect any kernel release prior to the of the fix identified by the commit 4fae8fd4adc7f4765463ddeb1a5fad23936432f6. Users running earlier kernels that instantiate MHI endpoints are potentially impacted.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires a local attacker with kernel‑level privileges to trigger MHI device creation failures. While the immediate impact is a resource leak, repeated exploitation could lead to cumulative denial of service. Given the low EPSS, the risk remains moderate but should not be ignored in environments where MHI devices are actively used.
OpenCVE Enrichment
Debian DLA
Debian DSA