Impact
The rtl8xxxu wireless driver in the Linux kernel contains a race condition in its RX request‑oriented work queue. When high‑traffic packet reception is ongoing, a worker task is scheduled to process pending USB request blocks (URBs). If the wireless interface is then stopped or disconnected before that worker finishes, the driver frees its private data structure while the worker still holds a reference, leading to a use‑after‑free that corrupts kernel memory. This flaw is a classic use‑after‑free (CWE‑825) and could allow an attacker with local access to manipulate the data and gain unrestricted kernel access.
Affected Systems
Any Linux kernel that includes the legacy rtl8xxxu driver and does not incorporate commit 620acb1e8037b73a457dc8ef20fc23fc7adcb405 or a downstream equivalent is vulnerable. Vendor‑distributed kernels and custom builds that ship with the rtl8xxxu module prior to the noted fix are affected. Updating the kernel to a version containing the commit or applying the patch directly to the source resolves the issue.
Risk and Exploitability
The CVSS base score of 7.8 reflects a moderate‑to‑high severity. The EPSS score of less than 1 % indicates a very low likelihood of exploitation so far, and it is not listed in the CISA KEV catalog. Exploitation requires active USB traffic and a subsequent disconnect, implying local access or direct control over the device. If successfully exploited, the use‑after‑free can corrupt kernel memory and enable a local privilege escalation to root.
OpenCVE Enrichment
Debian DSA