Impact
The vulnerability resides in the USB iowarrior driver of the Linux kernel. During a device disconnect, queued URBs are not stopped, leading to a use‑after‑free in the URB completion handler. This flaw can corrupt kernel memory and may be exploited to crash the system or achieve arbitrary code execution with kernel privileges, compromising confidentiality, integrity, and availability.
Affected Systems
Any system running a Linux kernel that includes the iowarrior USB driver before the applied fix. The vendor is Linux and the product is the Linux kernel; specific version data is not enumerated, implying that any kernel build lacking the recent commits may be vulnerable.
Risk and Exploitability
The EPSS score of less than 1% indicates a low probability of active exploitation, and the vulnerability is not listed in the CISA KEV catalog. It requires a local attacker or one who can supply a malicious USB device or trigger a disconnect, thus the attack vector is likely physical or local. Though no public exploit exists, the kernel memory corruption remains a high‑impact risk due to the potential for privilege escalation.
OpenCVE Enrichment
Debian DLA