Impact
A write use‑after‑free occurs in the Linux kernel’s HID:mcp2221 driver when an I2C/SMBus read operation stores the caller‑supplied buffer pointer in the device structure but never clears it after the transfer finishes or times out. When the caller later frees or reuses that buffer, the driver’s raw event handler later writes incoming data into the freed memory, corrupting kernel memory and potentially crashing or destabilizing the system. This flaw is a classic use‑after‑free, classified as CWE‑825.
Affected Systems
This flaw appears in all Linux kernels that include the mcp2221 HID driver before the patch that clears rxbuf. Every distribution or vendor that loads this driver on an unpatched kernel is vulnerable, meaning any Linux system with the MCP2221 USB driver enabled is affected.
Risk and Exploitability
Based on the description, the likely attack vector is local, requiring the attacker to have a connected MCP2221 device and the ability to initiate an I2C/SMBus read that triggers a delayed or spurious MCP2221_I2C_GET_DATA report. The CVSS score of 7.8 indicates moderate severity, while the EPSS score of < 1% signals a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would result in kernel memory corruption through a write use‑after‑free, which could lead to a system crash or privilege escalation.
OpenCVE Enrichment
Debian DSA