Impact
A race condition between the hardirq handler and a recovery worker in the Media TI VPE driver allows the worker to dereference a stream whose resources have already been released. The stream descriptor list and stream data structures are freed during stream teardown, but a queued recovery_work may still execute and access those freed pointers, causing a Use‑After‑Free. Such memory corruption within the kernel can be leveraged to modify kernel data or execute arbitrary code with kernel privileges.
Affected Systems
The flaw exists in the Linux kernel’s Media TI VPE driver – all kernel versions prior to the patch that implements the quiesce logic are affected. Any machine that loads this kernel and uses a TI VPE-compatible video processing engine is susceptible; the exact kernel version is not listed but the issue was fixed in the upstream kernel repository in the patch associated with this CVE.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability is rated high severity. The EPSS score of <1% indicates low predicted exploitation probability, and the flaw is not currently cataloged in CISA’s KEV list. However, exploitation requires an attacker who can trigger a FIFO overflow on the VPE device and coordinate a race with the IRQ handler, meaning local or privileged access to the device driver is typically needed. If achieved, the use‑after‑free could allow the attacker to corrupt kernel memory and potentially gain root or privilege escalation on the affected host.
OpenCVE Enrichment