Impact
The vulnerability is a use‑after‑free condition caused by the lock in the IIO DMA fence outliving the DMA buffer private structure. When the fence calls back after the buffer has been released, it accesses freed memory, which can lead to corruption of critical data or code paths. An attacker who can trigger this scenario could potentially overwrite memory with attacker‑supplied content, escalating privileges or causing a crash.
Affected Systems
The affected vendor is the Linux kernel, impacting all kernel versions that include the IIO buffer subsystem prior to the applied patch. No specific version list was given, so any Linux kernel builds that contain the unpatched IIO DMA fence implementation are potentially affected.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of less than 1% suggests a low likelihood of active exploitation at present. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or through privileged access to the IIO buffer subsystem; an attacker would need to influence the lifecycle of the fence and the buffer, a scenario that is feasible for privileged users or compromised firmware.
OpenCVE Enrichment
Debian DLA
Debian DSA