Impact
The vulnerability lies in the Linux kernel function sa_ul_probe(), which calls the DMA pool initialization function sa_init_mem() but ignores its return value. If the pool creation fails, the probe continues to configure the crypto module and populate child entries that rely on the allocated pool. This oversight can cause the kernel to reference an unallocated resource, leading to system crashes, memory corruption, or denial of service during boot or when the crypto module is loaded. The defect represents a failure to validate function return values, consistent with CWE-252, and does not provide a direct path for remote code execution.
Affected Systems
All Linux kernel releases that included the sa2ul crypto module prior to the fix. No specific version numbers are listed in the data.
Risk and Exploitability
The CVSS score is not provided and the EPSS score is below 1%, indicating a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited exploitation activity. Because the issue surfaces during module initialization, the attack vector would be a local attacker able to trigger or load the faulty crypto module. Overall risk is moderate due to potential kernel instability, but exploitation probability remains low.
OpenCVE Enrichment
Debian DLA
Debian DSA