Impact
The Linux kernel’s IIO buffer subsystem had a use‑after‑free bug in the release path of anonymous buffer handles. When a device was removed or hot‑unplugged, the buffer handle could hold the last reference to the IIO device. The release function would unlock the buffer mutex after calling iio_device_put(), which could destroy the device and the mutex simultaneously, resulting in a use‑after‑free during mutex unlock. An attacker exploiting this could crash the kernel or potentially execute arbitrary code with kernel privileges.
Affected Systems
All Linux kernel releases that contain the vulnerable iio buffer release code are affected. The specific affected versions are not listed in the advisory, so any kernel version prior to the 11th patch of the iio buffer helper must be considered vulnerable. Linux kernel code is distributed by the Linux Foundation and maintained by the kernel developers.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score is less than 1%, indicating a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog, so there is no known wide‑scale active exploitation. The likely attack vector is a local privileged process that can create or manipulate IIO buffer handles after the device has been removed. The fix resolves the race between mutex unlocking and reference dropping, eliminating the use‑after‑free.
OpenCVE Enrichment
Debian DLA
Debian DSA