Impact
The Linux kernel media driver for Zoran hardware contains a double‑free bug, where the video_device structure is freed twice during device teardown. This leads to kernel memory corruption that could be exploited to execute arbitrary code with kernel privileges or to destabilize the system.
Affected Systems
All Linux kernel releases that include the Zoran media driver before the patch are impacted. No specific version range is provided, so any kernel that compiles the zoran.c module without the fix is potentially vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 7.8 indicates a high‑severity flaw. The EPSS score of less than 1% suggests that the likelihood of a public exploit is low at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require a local attacker who can load or interact with the Zoran device driver, making the attack vector local rather than remote.
OpenCVE Enrichment
Debian DLA
Debian DSA