Impact
A NULL pointer dereference occurs in the Panthor DRM driver when a partial unmap of a GPU buffer object (BO) that has already been evicted is attempted. The driver fails to skip the partial unmap logic for the evicted BO, causing a dereference of the bo->backing.pages pointer which is NULL after eviction. This leads to an Oops and kernel panic, effectively taking the system offline.
Affected Systems
The vulnerability affects all Linux kernel releases that contain the Panthor DRM driver before the commit that introduces the fix. No specific upstream kernel version range is listed, so any kernel using the Panthor driver prior to the patch is potentially susceptible.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a historically low exploitation probability. However, an attacker would need the ability to invoke DRM ioctls that trigger a partial unmap of an evicted BO, implying a requirement for local or privileged access to the GPU subsystem. The impact is a denial of service via kernel crash, but there is no evidence of remote code execution or privilege escalation.
OpenCVE Enrichment