Impact
This CVE covers a use‑after‑free bug in the crypto_rng interface of the sun8i-ce driver for the Linux kernel. The bug was triggered by generating random data without correctly handling shutdown of DMA operations when a signal interrupted wait_for_completion_interruptible_timeout. The resulting memory corruption could lead to crashes or data leaks and was one of the drivers slated for removal.
Affected Systems
The affected component is the sun8i-ce crypto_rng driver bundled in the Linux kernel. The vendor is Linux; the product is the Linux kernel. The exact kernel versions that still contain the driver are not listed in the data, but any kernel build that incorporates sun8i-ce crypto_rng prior to the removal commit is vulnerable.
Risk and Exploitability
Because the bug requires the driver to be present and an attack vector is not explicitly disclosed, the vulnerability is likely exploitable in a local or privileged threat model, providing potential denial of service or memory corruption. The EPSS score is not available and it is not listed in the CISA KEV catalog, suggesting limited exploitation activity to date. The severity, while not quantified with a CVSS score, is high for kernel exploits, and the removal of the driver eliminates the flaw entirely.
OpenCVE Enrichment