Impact
The vulnerability lies in the Linux kernel's CEC (Consumer Electronics Control) driver. When a transmit operation is interrupted by a signal, the driver may cancel a pending delayed work item before scheduling the next work. The code then frees the data structure while a delayed work reference still points to it, creating a use‑after‑free situation that can crash the kernel or corrupt memory, enabling denial of service.
Affected Systems
Affected systems are any machines running a Linux kernel that includes the CEC driver. The CNA lists the vendor/product as Linux:Linux for all kernel versions, and no specific affected version range is provided. Administrators should consider all current kernel releases that ship the CEC module until the patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity flaw. The EPSS score is less than 1 % suggesting a low probability of exploitation in the wild at this moment, and it is not listed in CISA's KEV catalog. Nonetheless, the bug allows memory corruption that could be triggered by a malicious process or system error, so mitigation with a kernel update is recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA