Impact
In the Linux kernel, the i3c_master_unregister_i3c_devs() routine incorrectly clears the device descriptor before calling device_unregister(). During the unregister sequence, the uevent handler and the driver unbind process can observe a null descriptor, leading to a race that allows an attacker to leak kernel stack information via the malformed modalias and potentially trigger a use‑after‑free in driver remove callbacks. The vulnerability is a classic information‑leak combined with a use‑after‑free weakness.
Affected Systems
The flaw affects all Linux kernel releases prior to the commit that introduced defensive reference counting around i3c device unregistration. It applies to the generic Linux distribution kernel across all supported architectures, including x86, ARM, and others. Any device that implements the i3c master interface is potentially impacted. The patch is identified by commit 109995153898454c7795c2c299fd0a0b57456a4b, which adds an explicit get_device() reference before calling device_unregister() and clears the descriptor afterward.
Risk and Exploitability
The CVSS score of 7.8 denotes high severity, while the EPSS score of less than 1% indicates a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require local access to trigger the device unregister operation for an i3c master device. The race condition can expose sensitive kernel stack content to an attacker or cause a kernel panic, leading to information disclosure or denial of service. Based on the description, the primary attack vector is local privilege or specific device manipulation.
OpenCVE Enrichment
Debian DSA
Ubuntu USN