Impact
A flaw in the Linux kernel route device handling does not hold a reference to the device, allowing the device to be freed while still in use. This use‑after‑free can be triggered by an unprivileged local user sending specially crafted packets over AF_MCTP, leading to kernel memory corruption, abrupt system crash, or potentially enabling arbitrary code execution in kernel mode. The weakness is a classic use‑after‑free (CWE‑825).
Affected Systems
This issue affects all Linux kernel builds that include the mctp networking code and have not incorporated the recent commit that adds proper reference handling. The vendor is Linux; the product is the Linux kernel. No specific version numbers are supplied, but any kernel before the fix that contains the vulnerable code path is potentially vulnerable. Kernel changelogs or vendor advisories should be consulted to determine exact version coverage.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of < 1% signals a very low but non‑zero exploitation probability. The flaw is not listed in CISA KEV catalog. An attacker is an unprivileged local user on a system that supports AF_MCTP. By sending malicious packets that dereference a freed device, the attacker can trigger a use‑after‑free that may crash the system or, with a crafted payload, allow execution of code in kernel mode. Because no special privileges are required, any local user on a vulnerable kernel faces this risk if AF_MCTP traffic is allowed.
OpenCVE Enrichment