Impact
The media driver for the ov02a10 camera sensor has a use‑after‑free bug. During probe the endpoint handle is released before a property read still references it, allowing corruption of kernel memory. An attacker with local access or the ability to supply a crafted device tree could trigger this flaw, potentially executing arbitrary code or causing a kernel panic. The bug also improperly handles a missing property, causing the probe to fail so the device never registers, which can lead to a denial of service for systems that rely on the sensor.
Affected Systems
All Linux kernel versions that ship the media/i2c ov02a10 driver are vulnerable. The fix is in the mainline source and will arrive in downstream distributions that build a recent kernel. Any system running a kernel that includes the unpatched driver and has the ov02a10 device enabled is at risk.
Risk and Exploitability
With a CVSS base score of 7.8 the flaw is high severity, but its EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The issue can be leveraged only by attackers that can load or modify the device tree or gain local access, so the threat is somewhat constrained. The vulnerability is listed in CISA KEV as not present, yet the potential for privilege escalation and denial of service means the risk remains significant until a patch is in place.
OpenCVE Enrichment
Debian DLA
Debian DSA