Impact
A use‑after‑free flaw was introduced into the error path of the thermal_add_hwmon_sysfs function when a validity check was removed. The defect can corrupt kernel memory or cause the system to crash, potentially allowing an attacker with local access to gain kernel privileges or destabilize the system. The vulnerability arises from improper handling of a freed object that may still be in use.
Affected Systems
Linux kernel, all releases that contain commit 030a48b0f6ce before it was reverted. The fix is included in recent stable kernel releases that incorporate the revert of that commit.
Risk and Exploitability
Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, no public exploitation data exists yet. Nonetheless, the use‑after‑free flaw in a core kernel subsystem provides a high‑impact local attack vector; an attacker with physical or local logon access could trigger memory corruption leading to privilege escalation or denial of service.
OpenCVE Enrichment