Impact
The VFIO PCI driver leaves a dangling pointer in the device structure because the MSI permission table pointer is not cleared after a failed initialization, leading to a use‑after‑free. Subsequent openings of the same VFIO device can reuse the stale pointer, causing dereference of freed function pointers, and later attempts to free the already‑freed object result in a double‑free that can trigger a kernel panic.
Affected Systems
All Linux kernel builds that include the VFIO PCI driver are affected, regardless of version identifier in the given CPE. The vulnerability is inherent to the vfio/pci implementation across the Linux kernel source tree.
Risk and Exploitability
The EPSS score is < 1% and the CVSS score is 8.8, indicating high severity. The failure mode of a kernel panic and the possibility of executing arbitrary code make this a high‑risk flaw. It is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation yet. The attack requires local privileged access or the ability to open a VFIO device on the target system, so the likely attack vector is local privileged exploitation. An attacker with sufficient privileges could trigger the bug to compromise kernel integrity or force a reboot.
OpenCVE Enrichment
Debian DLA
Debian DSA