Impact
In the Linux kernel, a race condition in the Rust‑based devres module allows two concurrent revoker paths to interleave. The revocation performed by devres_release_all() via the release callback can occur at the same time as the drop logic executed on another CPU. If the revoker that does not claim the is_available swap returns immediately while the other is still running drop_in_place() on the inner data, a use‑after‑free can occur when a caller proceeds to drop adjacent resources that are still referenced. This bug is classified as CWE‑825. The resulting memory corruption can lead to kernel crashes or unstable behavior; the CVE description does not assert that arbitrary code execution is possible.
Affected Systems
Any Linux kernel that includes the Rust‑based devres implementation, particularly when devres_release_all() and Devres<DmaMappedSgt> or SGTable are compiled; all distributions shipping the current code path are affected.
Risk and Exploitability
The CVSS score is 7.8 and the EPSS score is below 1 %, indicating a low likelihood of exploitation. The issue is not listed in the CISA KEV catalog. Attackers would need to cause concurrent revocation on separate CPUs, a scenario that is plausible. The use‑after‑free could lead to memory corruption or system crash. The exact attack vector is not explicitly described, but it is inferred that concurrent revocations on different CPUs, such as simultaneous driver unloads, could trigger the race.
OpenCVE Enrichment