Impact
The Linux kernel bq24257 power‑supply driver can trigger a use‑after‑free when the device is removed. The driver registers a STAT‑pin interrupt that remains active until the devm cleanup runs after remove() returns. During removal the code cancels a delayed work queue item, but the threaded interrupt handler may still fire, rescheduling the work and dereferencing the already freed bq structure. This dereference of freed memory can corrupt kernel data or cause a crash.
Affected Systems
All Linux kernel installations that include the bq24257 driver prior to the specific kernel version range is listed, so any kernel build containing the vulnerable driver before the change – including custom builds – is at risk.
Risk and Exploitability
The CVSS score of 5.2 indicates a moderate impact, the EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of exploitation in the wild. However, the description does not detail specific threat levels, so based on the nature of the use‑after‑free it is inferred that exploitation would require the ability to trigger the device removal process. The impact could lead to kernel memory corruption or a crash, potentially allowing privilege escalation or denial of service, though these outcomes are not explicitly stated in the data.
OpenCVE Enrichment
Debian DSA