Impact
The vulnerability is a use‑after‑free in the at91_udc USB gadget driver (CWE‑825). In polled‑VBUS mode, the driver creates a self‑starting timer that repeatedly re‑arms itself. Neither the removal routine nor the probe error paths cancel this cycle. When the driver or work handler still runs and accesses the released structure, it simply crashes the kernel, which results in a denial of service to the local system.
Affected Systems
Linux kernels that include the at91 module polled‑VBUS mode (.vbus_polled set). All distributions or embedded builds shipping this driver with polled‑VBUS enabled fall under the scope of the vulnerability.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high severity. The EPSS score of less than 1% indicates it is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires local access to the device while the timer is active or to cause denial of service by crashing the kernel, and remote exploitation is not supported.
OpenCVE Enrichment
Debian DSA