Impact
The vulnerability is a classic use‑after‑free error in the Linux kernel driver for cx23885. The driver frees a netup_ci_state object while a work queue still holds a reference to it. When the work queue executes the pending task, it dereferences the freed memory, allowing an attacker to tamper with kernel memory or cause a crash. This flaw can be exploited to compromise system integrity and potentially gain privileged execution.
Affected Systems
The issue affects the Linux kernel and all kernel versions that contain the cx23885 media driver without the described fix. The exact kernel package names are not listed, but any installation that ships the vulnerable media driver is at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is below 1%, suggesting low current exploitation probability. The vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector is local: an attacker must be able to trigger the netup_ci_driver through userspace or hardware interaction, after which the kernel can crash or execute arbitrary code. The impact scope is system‑wide, affecting all processes running on the kernel. Routine updates are the recommended mitigation, as the kernel patch removes the race condition by cancelling work before freeing the state.
OpenCVE Enrichment
Debian DLA
Debian DSA