Impact
A race condition in the Linux twl4030 charger driver allows workers that run after the driver’s resources have been released to dereference a freed structure allocated by devm, leading to a use‑after‑free that can cause the kernel to crash.
Affected Systems
The vulnerability affects any Linux kernel that still contains the unpatched twl4030 charger driver code. All distributions with kernel builds that have not incorporated the upstream patch that cancels both workers before freeing the devm object remain vulnerable. The specific kernel releases are not listed in the advisory, but any version where the driver code is unchanged is impacted.
Risk and Exploitability
The CVSS base score of 4.4 indicates moderate severity, while the EPSS probability of exploitation is very low. The issue requires local control over the device removal to trigger the race, making it unlikely to be exploited remotely or by an unauthenticated attacker. The vulnerability is not listed in CISA’s KEV catalog, indicating no known exploitation activity.
OpenCVE Enrichment
Debian DSA