Impact
Based on the description, it is inferred that the vulnerability is a use‑after‑free in the Linux kernel’s RapidIO mport character device module. When a user space program frees the last reference to a DMA mapping, the kernel releases the mapping object and then incorrectly attempts to dereference it, potentially causing memory corruption that can crash the kernel or result in privilege escalation. This weakness is classified under CWE‑825.
Affected Systems
Based on the description, it is inferred that the bug resides in the Linux kernel,port character device before the commit that caches the mapping and the mutex. No specific kernel version is listed, so any Linux deployment that has the mport interface and has not applied the patch is vulnerable.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector is local interaction with the RapidIO mport character device from userspace. The CVSS score is 7.8, indicating a high severity, and the vulnerability is not in the CISA KE1% indicates a very low probability of exploitation. Attackers can trigger the use‑after‑free by interacting with the RapidIO mport character device from userspace, which requires local access to that device. Because the impact rises to a kernel panic or privilege escalation if the attacker can execute arbitrary code on the system.
OpenCVE Enrichment
Debian DSA