Impact
In the Linux kernel, the gdsc_unregister function fails to remove generic power domains that were registered during gdsc_init. This omission leaves dangling entries in the global gpd_list. When a driver that owns GDSCs is unloaded and later reloaded, the subsequent gdsc_init attempts to re‑register a domain that is already present, causing pm_genpd_init to return –EEXIST and resulting in a registration failure. The error can propagate up to device tree parsing or runtime driver loading, potentially leading to service interruption or a kernel warning/exception. The weakness involved is improper resource cleanup, which falls under the category of resource management faults.
Affected Systems
The flaw appears in all Linux kernel builds containing the Qualcomm generic power domain (GDsc) infrastructure. No specific kernel version range is listed, meaning the vulnerability applies to any kernel prior to the commit that introduced the fix. The affected code resides in the clock driver subsystem for Qualcomm devices, so any system that loads the corresponding clk driver modules (e.g., on Snapdragon or other QCOM SoCs) is potentially impacted.
Risk and Exploitability
The EPSS score is reported as less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low likelihood of exploitation in the wild. However, because the flaw can be triggered by a normal unload/rebind cycle of a kernel module, a local privileged user or a device manager with module unloading capability could reproducibly cause the error, leading to degraded system availability or a reboot loop. The lack of a public exploit suggests that the primary threat is internal or testing rather than external, but the impact on service continuity warrants a timely kernel update.
OpenCVE Enrichment
Debian DLA
Debian DSA