Impact
The roccat HID driver in the Linux kernel copies each incoming report with kmemdup() and stores the duplicate in a circular buffer slot. The allocation is released only when that slot is reused. When a roccat device is destroyed, the driver frees the device structure but leaves the duplicated reports stored in the buffer unreleased, creating a memory leak that may accumulate up to ROCCAT_CBUF_SIZE buffers per device. This results in increased heap usage that can exhaust system memory and degrade performance, constituting a denial‑of‑service condition. The flaw is a classic example of improper resource release (CWE‑772).
Affected Systems
Linux kernel distributions that include the roccat HID driver before the destructor fix are affected. Because the vendor information lists generic Linux kernels, the vulnerability may be present in any kernel branch that bundles the roccat driver without the patch. Administrators should determine whether their kernel version incorporates the fix; up‑to‑date kernels normally contain the constructor added in the patch series referenced in the provided commits.
Risk and Exploitability
The CVSS score of 3.3 and an EPSS score of less than 1% indicate low severity and a very low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. According to the description, an attacker must trigger the destruction of a roccat device, which generally requires privileged or local access to the device. Thus the attack vector is likely local privileged access, and the overall risk is confined to environments where such capabilities are possible. Even if exploited, the impact is limited to memory exhaustion rather than full system compromise.
OpenCVE Enrichment
Debian DSA