Impact
The vulnerability arises when the Xilinx DMA driver’s poll timeout routine is invoked with a zero microsecond delay and a condition that never meets its exit criterion. The driver then busy‑waits for an excessive period—on the order of minutes—before the timeout occurs, effectively stalling the CPU. This manifests as a denial of service on the affected system, potentially affecting all processes that require DMA operations and overall system responsiveness. The underlying weakness is a logical error that leads to unchecked resource consumption.
Affected Systems
This flaw affects the Linux kernel’s Xilinx DMA driver. While specific kernel release versions are not enumerated in the data, any installation that includes the unpatched xilinx_dma module on a Linux system is potentially vulnerable. Systems running embedded devices or servers that rely on Xilinx DMA for data transfer should review their kernel source and applied patches for this defect.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low likelihood of active exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, an attacker with local or remote access could trigger the stall by orchestrating a DMA operation that never satisfies the poll condition, leading to prolonged CPU utilization. Without an official CVSS score available, the risk is assessed as moderate: the impact is significant on availability, but the probability of exploitation remains low at present.
OpenCVE Enrichment