Impact
The saa7164 media driver in the Linux kernel incorrectly handles resource allocation failures during device initialization. When the PCI BAR memory region request fails, the driver increments the global device list but then decrements the device count and exits, leaving a dangling entry in the list. If the probe error path is later invoked, the device is freed but the global list still contains a reference to the removed device. This flaw can lead to kernel instability, including potential system crashes or corrupted state if later code accesses the stale list entry. The vulnerability is a classic example of improper resource deallocation.
Affected Systems
All Linux kernel configurations that include the saa7164 media driver are affected. The bug originates in the media subsystem of the kernel and is present in every kernel release that ships with the saa7164 driver until the patch is applied. No specific vendor or version details are listed beyond the generic Linux kernel designation.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity with high impact. The EPSS score is less than 1%, suggesting a low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local privilege or device presence; an attacker who can insert or manipulate a saa7164 device—typically a physical host or local user with kernel module loading rights—could trigger the faulty path. Exploiting this flaw would result in a denial of service or kernel crash, potentially allowing escalation to broader compromise if the crash leads to arbitrary code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA