Impact
The mtk‑mdp3 media driver in the Linux kernel contains a reference‑counting flaw. When the driver falls back to a platform device lookup after an scp_get() failure, it releases the obtained reference immediately. The driver still later performs an unconditional scp_put(), which underflows the reference count and may free a device still in use. This use‑after‑free can corrupt kernel memory and allows an attacker to execute arbitrary code in kernel mode, resulting in a full system compromise.
Affected Systems
All Linux kernel installations that include the mtk‑mdp3 media driver prior to the upstream commit that fixes the refcounting bug. The vendor product is the Linux kernel; no specific version range is supplied in the CNA data, so any kernel before the patch is potentially affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.4, indicating high severity. The EPSS score is reported as < 1 %, signifying a very low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector is local and requires an attacker who can trigger the probe failure path in the driver. This path is not explicitly documented, so the exact conditions for exploitation remain inferred from the description.
OpenCVE Enrichment
Debian DLA
Debian DSA