Impact
The Linux kernel HID sensor custom subsystem constructs a sysfs group for each custom sensor field. When creation of a later group fails, the previously created groups are left in place and the function returns an error without undoing them. These lingering groups can expose stale pointers that are later accessed through the enable_sensor sysfs entry, potentially causing kernel memory corruption. This weakness is classified as CWE‑772: Missing Release or Cleanup of Resource after Failure. Based on the description, it is inferred that an attacker who can cause a sysfs group creation failure may subsequently trigger kernel corruption by interacting with enable_sensor.
Affected Systems
All systems running the Linux compiled directly into the kernel or loaded as a module—are affected. This includes most mainstream Linux distributions that ship default kernels with this functionality. Versions of the kernel that have incorporated the commit adding cleanup logic for sysfs group creation, or those in which HID_SENSOR_CUSTOM has been disabled, are not affected.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% points to a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires privileged access to load or unload kernel modules or to compile and install custom sensor drivers, and relies on the failure of sysfs group creation. The exploit is confined to kernel space and therefore requires root or equivalent privilege; ordinary users cannot directly exploit the weakness.
OpenCVE Enrichment
Debian DSA