Impact
A use‑after‑free flaw was introduced in the Linux kernel’s thermal_add_hwmon_sysfs function when a validity check was removed during a commit cleanup. On the error path, the missing check allows an attacker with local or physical access to trigger kernel memory corruption. The resulting corruption can lead to kernel‑level privilege escalation or system instability.
Affected Systems
All Linux kernel releases that contain commit 030a48b0f6ce and have not yet incorporated the revert. Kernel versions newer than the fix contain the revert commit, restoring the required validity check and eliminating the vulnerability.
Risk and Exploitability
The CVSS score of 8.4 indicates a high‑severity local vulnerability, while an EPSS score of < 1% shows a low probability of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would require local or physical access to exercise the error path, but once achieved it could allow an attacker to gain kernel privileges or crash the system.
OpenCVE Enrichment
Debian DLA
Debian DSA