Impact
A premature release of a device‑tree node reference in the Linux kernel’s as3722 regulator driver leaves the driver’s of_node pointer dangling. The tainted pointer can be dereferenced later, creating a use‑after‑free condition (CWE‑825). The vulnerability is confined to kernel space and could corrupt kernel memory if the dangling reference is accessed. The CVSS score of 8.4 indicates a high severity impact on confidentiality, integrity and availability, while the EPSS score of less than 1% implies that exploitation is unlikely at the moment.
Affected Systems
All Linux kernel builds that include the CONFIG_REGULATOR_AS3722 driver are affected until the driver is patched. This includes any distribution that ships the driver in its kernel, regardless of kernel release version.
Risk and Exploitability
The risk of exploitation is low because the attack would require local access to influence the driver’s interaction with the device tree, such as loading a malicious device tree or forcing a driver unload/reload. The likely attack vector is local; however, the precise path of exploitation is inferred from the description and not explicitly documented in the advisory. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment
Debian DSA