Impact
A race condition exists in the Linux kernel media CEC subsystem where the function cec_receive_notify reads an exclusive follower pointer without holding the adapter lock. This flaw may allow an attacker to supply crafted HDMI CEC messages in a timing window that causes out‑of‑bounds reads or corrupts kernel state, potentially leading to denial of service or escalation to kernel privileges. The weakness is classified as Race Condition (CWE‑362).
Affected Systems
All Linux kernel variants that include the CEC driver are impacted, regardless of distribution or vendor. The vulnerability exists in the media/cec component of every kernel release until the superseding patch removes the race.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score is below 1 %, signalling a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an HDMI source that can transmit malicious CEC messages to the target; a false or delayed no‑follower check followed by message delivery can trigger the flaw. The flaw requires an attacker to be able to send HDMI CEC traffic and to time the race condition precisely, suggesting a local or remote interface that accepts HDMI input.
OpenCVE Enrichment
Debian DLA
Debian DSA