Impact
A use‑after‑free bug exists in the Linux kernel greybus raw driver. When a raw bundle is disconnected while an application still holds an open handle to its character device, closing that device triggers a reference‑count underflow in the kernel’s refcount module. This leads to a kernel panic that can bring the host offline, effectively denying service to all users on the affected system.
Affected Systems
The affected component is the Linux kernel greybus raw driver module. Any Linux kernel build that includes the greybus raw driver and contains a version before the fix satisfies the vulnerability requirement. Specific version numbers are not listed in the data, but the vulnerability is present in kernels prior to the patch commit referenced in the advisories.
Risk and Exploitability
The CVSS metric is not provided, and the EPSS score is unavailable; KEV does not list this vulnerability. The likely attack vector is local; an attacker who can open the raw bundle device and trigger a disconnect can cause the kernel to crash. No publicly documented exploits exist, and the vulnerability results in a denial of service rather than privilege escalation or remote code execution.
OpenCVE Enrichment