Impact
The vulnerability is a reference leak in the rockchip driver’s DP encoder enable function where the of_node reference is not properly released. This leads to an uncontrolled accumulation of device node references, potentially exhausting kernel memory or refcounted objects and causing instability or denial of service. The weakness falls under resource management failures.
Affected Systems
The issue is present in the Linux kernel, specifically the rockchip DRM driver module. No particular kernel versions are listed, so all affected kernel releases that contain the driver before the commit 396a193867c6 are potentially impacted. The vendor identified is the Linux kernel itself.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The bug is limited to the local environment where the driver is loaded, typically on devices with Rockchip SoCs; it does not expose a network access vector. Due to the non‑persistent nature of leaked references, an attacker would need physical or local system access and would likely trigger a denial of service through resource exhaustion rather than remote code execution.
OpenCVE Enrichment