Impact
In the Linux kernel interconnect subsystem, a failure in allocating a path name causes the path object to be freed with kfree() before the object is properly removed from the interconnect request lists. This leaves dangling pointers in the linked‑list structure, and subsequent calls to functions such as icc_get() or icc_set_bw() traverse or modify those corrupted lists, triggering a slab use‑after‑free and potentially crashing the kernel. The flaw is a data‑structure corruption resulting in kernel memory corruption.
Affected Systems
All Linux kernel implementations that include the interconnect driver and expose the functions icc_get() or of_icc_get_by_index() are affected. The common platform enumeration covers the entire kernel family, indicating that any distribution kernel without the fix is at risk, regardless of version or vendor.
Risk and Exploitability
The CVSS score of 7.8 reflects high severity. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The description does not detail an external attack vector, so it is inferred that exploitation likely requires local or privileged access to invoke the vulnerable interconnect functions, possibly via debugfs or privileged services. The impact is primarily denial of service through kernel crashes, with a potential for privilege escalation only if the attacker can leverage the crash to execute code in kernel mode, which is not explicitly stated in the CVE description.
OpenCVE Enrichment
Debian DSA