Impact
On Linux systems the kernel’s LDC channel maps request pages into a fixed‐size table. When a trigger fails, the descriptor remains marked ready and its cookies are never unmapped, leaking the entry permanently. Repeated failures under load reduce the 8192‑entry table until it empties, forcing the device to become unusable until a reboot. The leak also defeats retry‑based recovery, causing rapid memory exhaustion as descriptors are remapped on every retry. The impact is a systemic denial of service due to kernel memory exhaustion and lost I/O capability.
Affected Systems
The flaw affects all Linux kernel builds that include the sunvdc subsystem prior to the fix (not tied to a specific released version in the advisory). Any distribution using those kernels is potentially vulnerable unless the patched source code is in use.
Risk and Exploitability
No CVSS score is provided and EPSS is unavailable, indicating that exploit data is limited. The vulnerability requires the attacker to trigger repeated I/O failures, which is likely a local or privileged attack vector inferred from the kernel context. Although no exploits are listed and the vulnerability is not in the CISA KEV catalog, the high memory‑exhaustion risk and permanent corruption make it a significant threat when triggered.
OpenCVE Enrichment