Impact
In Linux kernel HID universal‑pidff driver, a failure of force‑feedback initialization after the device is started causes the driver pointer to be cleared while the HID core does not revert the device start. The resulting /dev/hidraw character device remains open but points to freed kernel memory, and opening that device triggers a use‑ callback, allowing an attacker with local access to corrupt kernel memory and potentially execute arbitrary code or elevate privileges.
Affected Systems
All Linux systems that ship a kernel containing the universal‑pidff driver before the fix are affected. The vulnerability manifests when the HID device has no input reports or other conditions that force the force‑feedback init path to fail. No other vendors or products are listed in the CNA data. Affected distributions include any that have not yet applied the patch committed in commit 01d9874e84d3ab78fd212ad822412eb3af84497f.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity while the EPSS score of < 1 % shows a historically low exploitation likelihood. The vulnerability is not in CISA KEV. Exploitation requires to open a surviving /dev/hidraw* entry; the use‑after‑free can be triggered by a crafted device that causes force‑feedback initialization to fail. Successful exploitation can lead to kernel memory corruption and local privilege escalation.
OpenCVE Enrichment
Debian DSA