Impact
A use-after-free flaw exists in the OMAP2430 musb driver, where the OF node is released before its last use during probe. This can corrupt kernel memory, potentially leading to a system crash or arbitrary kernel code execution.
Affected Systems
The vulnerability is present in all Linux kernel releases that include the OMAP2430 musb driver before the recent fix. Devices that embed the Texas Instruments OMAP2430 SoC and use the musb driver are impacted. No specific kernel versions are noted in the advisory, so all vulnerable kernels are assumed affected.
Risk and Exploitability
The CVSS score of 8.4 signals high severity, while the EPSS score of less than 1% indicates a low but non-zero likelihood of exploitation. The issue is not listed in the CISA KEV catalog. The likely attack vector is local or via a connected USB device that triggers device probe, requiring privileged or root access to fully exploit the memory corruption. Exploitation requires local root or kernel-level permissions, as the driver runs in kernel context.
OpenCVE Enrichment
Ubuntu USN