Impact
An implementation of the Linux kernel’s Industrial I/O (IIO) subsystem introduced a custom release function for its DMA fences that frees the memory with kfree(). Because kfree() is not RCU-safe, a use-after-free condition can arise when the fence is accessed after it has been freed, potentially leading to a kernel crash or arbitrary code execution in privileged mode. This is a classic Use-After-Free flaw, corresponding to CWE-416.
Affected Systems
All Linux kernel installations that contain the IIO DMA fence code are potentially affected, including kernels distributed by major Linux distributions. Affected kernel versions are not specified, so any kernel in which the iio_dma_fence structure is compiled and used by IIO device drivers is included.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability, but the EPSS score of less than 1 % suggests a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector would require a privileged or local attack that can trigger the custom release path in the IIO subsystem, but this inference is drawn because the precise exploitation methods are not detailed in the CVE data. Given the low exploitation probability, the overall risk is medium, but the impact remains high if an attacker succeeds.
OpenCVE Enrichment
Debian DLA
Debian DSA