Impact
The flaw is a race condition (CWE‑364) between ravb_ptp_interrupt() and ravb_ptp_stop() that results in a use‑after‑free of the PTP clock object. Once the clock can still dereference the pointer, leading to memory corruption and kernel crashes, impacting kernel integrity andThe CVSS score is 7.8, indicating a high-level severity. The EPSS score is below 1%, showing a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The use‑after‑free could be exploited by a local or privileged user who can trigger the relevant interrupts, but no public exploits are documented.
Affected Systems
The vulnerability is present in Linux kernel builds that contain the ravb networking driver before the patch that serializes the PTP clock teardown. No specific affected‑version range is listed, so any kernel incorporating that code path could be at risk.
Risk and Exploitability
The CVSS score of 7.8 classifies this flaw as high severity, while the EPSS score below 1% suggests a low probability of exploitation. Because the flaw is a local use‑after‑free race condition, a privileged or local attacker who can trigger PTP interrupts during teardown could potentially crash the kernel or, in a worst‑case scenario, achieve privilege escalation. The vulnerability is not part of the CISA KEV catalog, so there are currently no publicly reported or weaponized exploits.
OpenCVE Enrichment
Debian DSA