Impact
The flaw occurs in the Linux kernel’s XHCI USB controller subsystem where the debug TTY driver registers and then fails. The failure causes a global driver pointer to remain dangling while the driver object is freed. During module unload, the cleanup routine attempts to unregister the dangling driver, resulting in a use‑after‑free in kernel space. This can corrupt memory, trigger a kernel panic, and, as the driver owns kernel memory, it is inferred that an attacker who can load or unload the module could gain elevated privileges.
Affected Systems
All Linux kernel installations that include the XHCI debug TTY driver and have not incorporated the upstream patch are affected. No specific kernel version range is provided, so any mainline kernel lacking the commit that fixes the dangling pointer is vulnerable. Distributions shipping a default kernel without the patch inherit the flaw.
Risk and Exploitability
The CVSS score is not supplied, but a use‑after‑free in kernel space is normally high severity. The EPSS score is unknown, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is likely local, requiring the attacker to have the ability to load or unload kernel modules. Although direct proof of privilege escalation is not in the text, the nature of the flaw suggests that exploitation could lead to kernel‑level code execution or crash.
OpenCVE Enrichment
Debian DSA