Impact
In the Linux kernel IPMI subsystem, a use‑after‑free bug occurs when the command‑receiver structure is freed while a reader still holds a reference to it. This race originates from the removal of the synchronize_rcu() barrier that previously separated the unlinking of command receivers from their deallocation, leaving the list traversed under plain RCU. The resulting memory corruption can compromise kernel memory integrity and may trigger a crash or unexpected behavior. The flaw is classified as CWE‑825, indicating a race condition that can lead to a use‑after‑free vulnerability. While the description does not explicitly state arbitrary code execution, the kernel memory corruption could potentially be leveraged to elevate privileges if an attacker can influence the dereferenced data.
Affected Systems
The affected product is the generic Linux kernel build that includes the legacy IPMI interface code without the commit restoring the synchronize_rcu() barrier. No specific vendor or product variants are listed, and affected kernel versions are not enumerated, so any kernel containing the vulnerable code should be considered at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of <1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to have the ability to send IPMI commands to the target’s BMC to trigger the flaw. If such access is achieved, the memory corruption could enable the attacker to interfere with kernel execution paths or elevate privileges.
OpenCVE Enrichment