Impact
The vulnerability resides in the Linux kernel’s NXP PIT clocksource driver. If cpuhp_setup_state fails after request_irq has be successfully called, the path skips the IRQ release step and jumps directly to unregistration logic, leaving the IRQ line registered but not freed. The interrupt handler’s dev_id then points to a structure that is freed, subsequent interrupt on that IRQ would dereference the stale pointer, resulting in a use‑after‑free that an attacker could potentially exploit to gain arbitrary code execution in the kernel. This flaw is identified as CWE‑825, an improper resource release leading to a use‑after‑free.
Affected Systems
All Linux kernel configurations that include the nxp_pit driver and enable it during boot or CPU hotplug are susceptible. Any kernel build that lacks the recent commit fixing the cleanup path is vulnerable, regardless of kernel version, as the issue is present in the mainline code base until the patch is applied.
Risk and Exploitability
The flaw is classified as high severity, while the EPSS score of <1% indicates a very low likelihood of exploitation. It is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker would need local privilege and the ability to trigger a failure in cpuhp_setup_state, such as by manipulating CPU hotplug or inducing a setup failure, and then generate an interrupt on the leaked IRQ after the driver structure has been freed. No publicly available exploits are documented, but the combination of a serious impact and potential for privilege escalation warrants timely remediation. This flaw maps to CWE‑825, indicating a resource release error that can lead to use‑after‑free.
OpenCVE Enrichment