Impact
This kernel bug causes an SPI controller in target mode to continue an active transfer when the system is suspended. The ongoing transfer is not aborted, leaving the hardware in an inconsistent state. As a result the system can freeze or fail to resume cleanly, effectively creating a denial‑of‑service situation for the host.
Affected Systems
All Linux kernel builds before the published fix are vulnerable. The issue applies to the kernel source for all distributions that ship the unpatched version, as the affected code path is common to all Linux kernels.
Risk and Exploitability
The exploitability is limited to systems that are powered on and then suspended while an SPI target transfer is in progress. The vulnerability requires kernel privileges to influence the transfer state, so it is not trivially exploitable by an unprivileged process. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the impact of a successful exploit is a system freeze or failed resume.
OpenCVE Enrichment