Impact
During device probing on boards that support dual time‑slot interfaces, the em28xx media driver registers audio‑only extensions before the optional secondary device is fully constructed. The driver then creates a duplicate device that inherits the audio‑only flag and is inserted into a global device list. Because the primary and secondary devices are linked independently, the secondary can be freed during a disconnect while its list node remains reachable, leading to a use‑after‑free condition. If an attacker can trigger the probe and disconnect sequence, they could exploit kernel memory corruption, potentially allowing arbitrary code execution at kernel privilege level.
Affected Systems
This weakness is found in the Linux kernel’s em28xx media driver. Any distribution or build of the Linux kernel that includes the unpatched em28xx code is affected. The advisory references commit identifiers that applied the fix, but no specific version range is listed; therefore, systems running pre‑fix kernels that provide em28xx support are at risk.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low probability that this vulnerability will be exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require local privileged access to invoke the driver’s probing logic, as remote exploitation pathways are not documented. Because the bug can lead to a kernel crash or arbitrary code execution, its potential impact is severe, but the overall likelihood of attack remains low at present.
OpenCVE Enrichment
Debian DLA
Debian DSA