Impact
In the Linux kernel the charlcd driver with CONFIG_CHARLCD_BL_FLASH schedules a delayed backlight work item before the driver’s misc device is registered. If registration fails, the driver frees its internal object while the delayed work still references it, creating a use‑after‑free condition that can lead to arbitrary memory corruption and system crashes. The weakness is a classic improper release of resource flaw, CWE‑825.
Affected Systems
All Linux kernel builds that compile the charlcd driver with the CONFIG_CHARLCD_BL_FLASH option enabled are affected, including any distribution kernel that has not yet integrated the fix that cancels the delayed work during deinitialization. The vulnerability resides in the core Linux kernel driver code, not in a single vendor’s custom distribution.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score is less than 1% and it is not listed in the CISA KEV catalog, suggesting a low likelihood of current exploitation. Based on the description, it is inferred that the attack vector is limited to local or privileged accounts that can trigger a registration failure; there is no exposed user‑space interface to induce the failure. Consequently, the overall risk remains moderate to low for typical production systems, but any system running an unpatched kernel with this configuration should be upgraded or patched promptly.
OpenCVE Enrichment
Debian DSA