Impact
In the DRM subsystem of the Linux kernel, a race condition exists when the device registration routine partially fails after partially registering a minor number. A user‑space process can open the device that is still considered live, enter a critical section, and then the kernel begins to tear down the device resources. Because the unplug flag is never cleared, the ioctl that follows may act on resources that are in the process of being deallocated, which can corrupt kernel memory or lead to a crash.
Affected Systems
The vulnerability applies to any Linux kernel build that contains the unpatched drm_dev_register path. The specific kernel releases that are affected are not enumerated in the advisory, and the fix is introduced in later commits. Therefore, any kernel version that predates the commit introducing drm_dev_synchronize_unplug() is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 marks this as high severity. The EPSS score of less than 1% indicates a low probability of widescale exploitation, and the issue is not listed in the CISA KEV catalog. The likely attack vector involves a local user triggering a failed device registration and then invoking an ioctl on the partially registered device. No documented remote exploitation pathway exists.
OpenCVE Enrichment
Debian DLA
Debian DSA