Impact
During driver initialization the uvesafb module registers a v86d connector callback before attempting to register its platform driver. If platform_driver_register() fails, the function exits early while the callback remains registered. Subsequent cleanup in the device failure, leaving a dangling reference that can cause a kernel crash or reboot when the callback is invoked. The weakness is an improper release of a resource, identified as CWE‑772, and the primary impact is a loss of system availability via kernel instability, not code execution or privilege escalation.
Affected Systems
All Linux kernel builds that include the legacy uvesafb driver before the regression fix are potentially affected. The, so any kernel that still ships the old driver implementation before the cleanup patch remains at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a medium‑to‑high severity. The EPSS score is below 1 %, suggesting a low probability of exploitation under current conditions, and the vulnerability is not listed in the CISA KEV catalog. To exploit this issue an attacker would need to cause the uvesafb driver initialization to fail during boot, which is generally a local scenario that may depend on configuration or hardware conditions. Based on the description, it is inferred that the orphaned callback could trigger a kernel crash or reboot when invoked, leading to availability disruption. However, no remote exploitation or privilege escalation is supported by the available data. The overall risk is moderate and primarily concerns environments that use this specific driver and encounter a registration failure at system startup.
OpenCVE Enrichment
Debian DSA