Impact
The vulnerability stems from a missing call to rc_free_device() during deregistration of RC devices in the kernel's CEC core. This oversight causes allocated rc devices to remain referenced, leading kmemleak to report unreferenced objects after component unbinding, such as dw-hdmi. The leak can accumulate over time, potentially exhausting kernel memory and impacting system stability.
Affected Systems
All Linux kernel releases that included the faulty logic—specifically before the merge of commit dccc0c3ddf8f—are affected. The issue manifests in any distribution using the Linux kernel where CEC and related drivers (e.g., dw-hdmi) are active. Because the commit was applied in stable branches, newer kernel builds should be safe, but older kernels remain vulnerable.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low exploitation likelihood in the wild. Nevertheless, the unchecked memory leak can silently consume resources, escalating to denial of service if left unchecked. No public exploit is known, but patching remains advisable to prevent potential availability degradation.
OpenCVE Enrichment
Debian DLA
Debian DSA