Impact
The Linux kernel contains a flaw in the lp5860 LED driver where a failed initialization path causes an already unlocked mutex to be unlocked again. This double unlock can corrupt the internal state of the mutex. It is inferred that such corruption may trigger a kernel panic or other undefined behavior that would interrupt system availability.
Affected Systems
All Linux kernel deployments that include the lp5860 LED driver are potentially affected. The specific kernel versions are not enumerated in the provided sources; the bug exists in any kernel build that compiles this driver. Users running mainstream distributions that ship the default kernel, such as Ubuntu, Fedora, Debian, or RHEL, may be impacted if the driver is enabled.
Risk and Exploitability
The EPSS score is listed as < 1 %, and the vulnerability is not in the CISA KEV catalog, indicating a low likelihood of exploitation in the wild. It is inferred that an attacker would need to run code with kernel‑level privileges or manipulate the device tree during initialization to trigger the failure condition. Without such privileged access or a malicious device tree, the attack surface is quite narrow.
OpenCVE Enrichment