Impact
A use‑after‑destroy bug in the Linux kernel’s ov7740 camera driver caused the driver’s mutex to be destroyed before its V4L2 control handler was freed, leading to a kernel panic during device teardown. The driver also called the cleanup function twice, triggering a double‑free that corrupts kernel memory. The flaw does not provide privilege escalation or remote code execution; its primary impact is the loss of availability due to a kernel crash, which could halt all processes on a affected system. The likely attack vector involves triggering the driver's removal sequence, which requires local interaction with the device or privileged access to the I2C bus. Based on the description, it is inferred that an attacker would need to unload the driver or manipulate the device’s state to cause the bug.
Affected Systems
All Linux kernel builds that include the ov7740 driver and have not applied the patch at commit 09453b467990e8ef8fe09f45a685f9a625248d33 are vulnerable. The affected versions encompass any kernel where the ov7740 sub‑device is enabled, regardless of major or minor version, since the vulnerability exists in all pre‑patched releases that contain the driver.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity bug, yet the EPSS score of less than 1% reflects a very low current probability that this vulnerability will be exploited. It is not listed in CISA’s KEV catalog. Based on the description, it is inferred that exploitation would require local control of the device or the capacity to trigger its removal sequence, which likely necessitates privileged access to the I2C bus or the ability to unload the driver. No remote exploitation or privilege escalation is described, so the main risk remains a denial‑of‑service via a kernel panic.
OpenCVE Enrichment
Debian DLA
Debian DSA