Impact
The flaw originates from an early release of a v4l2_device reference in the go7007 driver while a userspace process still holds an open PCM capture. The go7007_snd_remove() routine drops the reference immediately after calling snd_card_free_when_closed(), which can occur before the V4L2 release path has fully finished cleaning up. This allows the kernel’s ALSA callbacks to access freed memory and trigger a use‑after‑free condition that could crash the kernel or allow an attacker to execute code in kernel mode if the freed memory is reused maliciously.
Affected Systems
All Linux kernel installations that contain the go7007 driver are affected. Specific kernel version ranges are not listed in the CVE data, so any actively maintained kernel that includes this driver should be examined for the pending fix.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of <1% suggests exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. Because the fault can be triggered by a local user who opens a PCM capture, the attack vector is local privilege or a local software component that has permission to access the device. A successful exploitation could lead to a kernel crash or privilege escalation to arbitrary kernel execution.
OpenCVE Enrichment
Debian DLA
Debian DSA