Impact
The Renesas I3C driver performs asynchronous data transfers without verifying that a transfer structure remains valid when the interrupt handler processes it after a timeout. This memory, resulting in a use‑after‑free condition that can crash the kernel. The flaw is categorized as a memory corruption weakness (CWE‑825) and its primary consequence is an availability impact due to a kernel panic.
Affected Systems
The issue is present in the Linux kernel’s Renesas I3C driver for Renesas I3 i3c renesas module and has not applied the patch is potentially affected. No particular kernel version range is specified in the advisory, so all kernels that include the driver remain at risk until the fix is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating high severity, and an EPSS score of less than 1%, suggesting a low probability of exploitation. It is not listed in the CISA KEV catalog. Exploitation would require a timed‑ freed structure, which is non‑trivial but possible. Successful exploitation would cause a kernel crash, resulting in a denial‑of‑service impact.
OpenCVE Enrichment