Impact
The flaw is a race condition in the ZynqMP DMA driver where the runtime power management (PM) subsystem could transition the device to suspend while the remove/unbind path is executing. This race can leave the DMA device in an inconsistent state, leading to crashes, hardware corruption or denial of service by triggering undefined behavior in the driver code. The weakness is a classic race condition vulnerability (CWE‑420).
Affected Systems
The vulnerability affects Linux kernel builds that contain the zynqmp_dma driver. Systems using boards that load the module, such as those incorporating the ZynqMP SoC, are impacted. No specific kernel release numbers are supplied by the CNA; the fix is present in the latest kernel sources as referenced by the commit logs.
Risk and Exploitability
The EPSS score of less than 1 % indicates a very low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. The issue requires local access to the host machine and a capability to unload or bind the kernel module. While the risk is limited, failure to patch could allow a local attacker to destabilize the system by unloading the driver while it is active, potentially causing a reboot or crash. The lack of a public exploitation vector suggests the threat is mainly operational rather than a direct remote payload.
OpenCVE Enrichment