Impact
A race condition exists in the Linux kernel’s mcp2221 HID driver where device I/O is not halted before the hardware teardown. When a probe fails or the device is removed while I/O remains active, the kernel may access freed memory, causing a use‑after‑free that can crash the kernel. The resulting crash represents a denial of service on the affected system.
Affected Systems
All Linux kernel builds that ship the unpatched mcp2221 driver are impacted. Systems that load the mcp2221 driver and have a USB HID device capable of being removed or that can trigger a probe failure are at risk until the kernel is updated with the commit that stops I/O before teardown. This includes most mainstream distributions that load the generic mcp2221 module.
Risk and Exploitability
The CVSS score of 3.9 indicates low severity, and the EPSS score of <1% shows that exploit attempts are unlikely. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local or device‑level access: an attacker would need to control the USB HID device connected to the target or have the ability to force its removal. This inference is based on the description that the issue occurs during device cleanup.
OpenCVE Enrichment