Impact
The atlas‑sensor driver in the Linux kernel frees its data‑ready IRQ resources while a threaded handler may still be queued. The handler, waiting on conversion‑complete interrupts, dereferences freed data, resulting in a classic Use‑After‑Free (CWE‑416) that can corrupt memory or allow arbitrary code execution.
Affected Systems
The vulnerability affects the atlas‑sensor driver present in all Linux kernel builds prior to the fix. No specific kernel version range is listed in the advisory, but any kernel containing the original signature of this driver is at risk. The issue was identified by static analysis and subsequently patched in later kernel commits.
Risk and Exploitability
The CVSS score of 7.8 classifies the flaw as high severity, yet the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not cited in the CISA KEV catalog. Exploitation would likely require a local privileged context to trigger device removal while the threaded work remains pending. Overall, the risk is moderate but can be effectively reduced through patching.
OpenCVE Enrichment
Debian DLA
Debian DSA