Impact
The vulnerability lies in the Linux kernel Thunderbolt Alternate Mode removal routine. When a device is removed, the function drops plug and cable references before draining the scheduled work queue. The work handler later dereferences those already freed objects and can re‑queue itself in error paths, creating cause a kernel panic or potentially allow an attacker to execute arbitrary code with kernel privileges.
Affected Systems
All Linux kernels that include the unpatched thunderbolt type‑C handling code are impacted. No specific version range is listed in the CNA data, so any kernel before the commit that fixed the issue may be vulnerable. The affected product is the Linux kernel itself.
Risk and Exploitability
The score of 7.0 on the CVSS scale denotes high severity, while the EPSS value of less than 1% indicates a very low probability of real‑world exploitation at this time. The flaw is not listed in the CISA The likely attack vector is local hardware manipulation: an attacker would need to connect a malicious Thunderbolt or USB‑C device to the affected system to trigger the race condition.
OpenCVE Enrichment