Impact
In the Linux kernel media driver em28xx, a use‑after‑free bug allows a corrupted global device list to occur when a device with has_dual_ts=1 is disconnected. During disconnect the driver removes only the device’s own list entry, leaving the next element’s list pointer dangling. When a subsequent device probe adds a new device, the list corruption triggers a BUG, leading to a kernel panic.
Affected Systems
All systems running a Linux kernel that includes the em28xx driver before the patch that removes the dangling devlist reference are affected. The flaw is inherent in the kernel code and therefore any distribution shipping a kernel version with the em28xx module prior to the fix is vulnerable, irrespective of other components or services.
Risk and Exploitability
The EPSS score is below 1%, indicating a low probability of exploitation and the vulnerability is not listed in CISA KEV. The bug is triggered by a USB device that supplies fuzzed endpoint descriptors that cause the driver to execute the is_audio_only + has_dual_ts path. Exercising this path results in a list corruption and kernel crash, producing a denial‑of‑service attack vector.
OpenCVE Enrichment
Debian DLA
Debian DSA