Impact
The rcar thermal driver calls thermal_zone_device_enable() before verifying that thermal_zone_device_register_with_trips() succeeded. If registration fails, the priv->zone pointer is set to an error value; invoking enable on this value results in a dereference of a potentially invalid pointer, which can trigger a kernel oops, crash, or data corruption. This flaw is a classic error‑encoded pointer dereference and can destabilize the kernel when the driver is loaded.
Affected Systems
All Linux kernel builds that incorporate the rcar thermal driver source before the patch are vulnerable. The vendor is Linux and the affected product is the Linux kernel itself; no specific version range is provided, so any unpatched build may be at risk.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector is local privileged access that forces a registration failure, leading to an error pointer dereference. The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. Exploitation would likely require local privileged access to manipulate the driver’s initialization path or force a registration failure. If successful, the flaw could cause a kernel crash or data corruption, affecting system availability and integrity. The attack vector is local, potentially through device firmware or privileged software interacting with the thermal subsystem.
OpenCVE Enrichment
Debian DLA
Debian DSA