Impact
A use‑after‑free flaw in the Linux kernel’s LP8727 power‑supply driver allows a delayed work task to be scheduled after the driver has released the IRQ and freed‑arm the work, and when the device is removed, the work may run on a freed pointer, potentially crashing the kernel or corrupting memory. The flaw represents a classic CWE‑825 scenario that exposes the kernel to arbitrary memory corruption from privileged driver code.
Affected Systems
Any installation of the Linux kernel that includes the LP8727 power‑supply driver utilizes commit 6ab3128292df67295de1b2a86f21d89cf6612a7e. The driver is used on systems equipped with the LP8727 power‑management chip, and no specific kernel version information is available for impacted kernels.
Risk and Exploitability
The CVSS score of 8.4 denotes high severity. EPSS remains < 1%, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be local privilege or a maliciously constructed interrupt. Successful exploitation could lead to kernel crashes, memory corruption, or privilege escalation. However, achieving a successful attack would require a crafted interrupt or manipulation of the LP8727 device, which is unlikely in normal operation.
OpenCVE Enrichment
Debian DSA