Impact
A flaw in the Linux kernel’s USB gadget UVC driver causes two pointers, uvc->control_req and uvc->control_buf, to stay dangling after they are freed in the bind and unbind functions. This results in a use‑after‑free that corrupts kernel memory and can lead to a crash or, in worst cases, local privilege escalation.
Affected Systems
The vulnerability affects and has not yet incorporated the upstream fix. Specific kernel version numbers are not listed, so all kernels shipping an unpatched UVC module are potentially impacted. It is inferred that systems that disable or omit the UVC gadget driver are not affected, as no UVC code would execute.
Risk and Exploitability
The CVSS base score of 7.8 indicates a medium‑to‑high impact, while the suggests a low current exploitation likelihood. The vulnerability is not in CISA’s KEV catalog. Attackers would need to trigger the buggy bind or unbind paths, likely by interacting with the USB gadget interface or by loading the module in a privileged context. No publicly available exploits are documented, but successful exploitation could cause a kernel crash or enable privilege escalation.
OpenCVE Enrichment
Debian DSA