Impact
The Linux kernel staging IPU7 media driver contains a use‑after‑free flaw (CWE‑825) in its async notifier registration path. When the driver registers the async notifier and a later probe step fails, only the device resources are cleaned up while the notifier remains registered in the global list. The notifier then points to a freed device structure, causing list corruption the next time the notifier list is walked and typically resulting in a kernel crash bug that does not, as currently described remote code execution. The attack vector is not explicitly stated in the CVE data; it is inferred to be local, requiring an attacker to trigger a probe failure via interactions with the media subsystem or hardware configuration.
Affected Systems
All Linux kernel releases that include the staging/ipu7 driver before the commit that corrects the cleanup of the async notifier on a probe error path are affected. No specific version range is listed, so any kernel version that contains the pre‑patch code is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 classifies this as a high‑severity flaw, while the EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation in the wild. but there is no evidence that it enables remote or privileged exploits. The vulnerability is not listed in the CISA KEV catalog. Because the flaw can destabilize the kernel, it poses a significant operational risk to systems that rely on the IPU7 media functionality.
OpenCVE Enrichment