Impact
A double‑free bug exists in the Linux kernel’s V4L2 video device registration path. When device_register fails, the kernel frees the same video_device structure twice, corrupting kernel memory. This flaw can cause crashes or memory corruption and is identified as CWE‑1341.
Affected Systems
Linux kernel implementations that contain the original commit (2a934fdb01db6458288fc9386d3d8ceba6dd551a) and have not applied the revert. Any that kernel and employing V4L2 drivers is affected.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. With an EPSS score of less than 1%, the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires a local user to trigger a V4L2 video device registration attempt that fails, leading to a double‑free. Remote exploitation is unlikely due to the need for kernel-level interaction.
OpenCVE Enrichment
Debian DSA