Impact
A use‑after‑free flaw in the AMT subsystem of the Linux kernel allows pending delayed work items to run against a freed device structure after the AMT device has been removed. This bug can cause a kernel crash or corrupt memory. The primary impact is disruption of kernel operation and, depending on the context, could be leveraged to gain elevated privileges if an attacker can trigger the race condition.
Affected Systems
Any Linux kernel that includes AMT support is affected. The exact kernel versions are not specified, so all builds with the AMT driver should be considered vulnerable until the patch is applied.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in CISA KEV, indicating that public knowledge of exploitation is limited. The flaw requires a local or privileged attacker to cause the device removal race. However, a kernel crash constitutes a serious denial‑of‑service event, and memory corruption could enable further attacks if the attacker can influence the freed memory region.
OpenCVE Enrichment