Impact
The Linux kernel hid-sony driver for Sony Guitar Hero Live dongles has a use-after-free bug. When the device or driver is removed, the driver frees a timer and a USB Request Block while an outstanding timer callback may still execute. The timer callback re-activates the freed structure, leading the kernel to reference memory that has already been released, which triggers a crash. This results in a local denial-of-service: the kernel panics and a reboot is required. No remote compromise or data exfiltration is possible.
Affected Systems
Linux guard against the unbind race are affected. Any system that loads the hid-sony driver and supports a Guitar Hero Live dongle (VID 0x1430, PID 0x07BB) is at risk. The flaw does not affect other HID drivers or USB devices.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is below 1%, implying a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is the machine to plug or unplug the dongle, or root privileges to unload the module during the race window. There is no documented network or remote privilege escalation path.
OpenCVE Enrichment
Debian DSA