Impact
A race condition in the Linux trusted TPM subsystem causes the TPM device reference to be dropped and the digest array to be freed before the trusted key type is unregistered. While key_type_lookup() holds a read lock on key_types_sem, unregister_key_type() later acquires a write lock. If these operations interleave on different CPUs, a key operation can dereference the freed digest array during a PCR extend callback, triggering a slab-use-after-free and kernel crash. The weakness is identified as CWE-825, and the kernel memory corruption can result in an unclean system reboot, effectively a denial of service.
Affected Systems
Linux kernels that include the trusted TPM subsystem. No specific version range is listed; any unpatched kernel that has the trusted TPM module enabled is affected.
Risk and Exploitability
The CVSS score of 7.8 combined with an EPSS score of less of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying no publicly known exploits. It is inferred that an attacker would need to gain privileged or kernel execution and trigger the race during a TPM module unload, leading to a kernel crash and denial of service.
OpenCVE Enrichment
Debian DSA