Impact
In the Linux kernel’s cpuidle subsystem, the fault arises when a full device‑tree node path string is allocated and a pointer to its basename is stored for the power domain structure. During deallocation, the code mistakenly calls kfree() on this basename pointer rather than on the original allocation block, resulting in an invalid free and corrupting kernel memory. This corruption can trigger a kernel panic or allow an attacker to overwrite critical kernel data structures, potentially leading to privilege escalation or denial of service.
Affected Systems
The vulnerability exists in any Linux kernel that has not incorporated the repository fix. Because the flaw is located in core kernel source, all kernel builds that compile this code—across distributions and versions—are potentially affected until the patch is applied.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity for kernel memory corruption, while an EPSS score of <1% suggests the current likelihood of exploitation is low. The flaw is not listed in CISA KEV. Exploitation would require local kernel privilege or the ability to load a malicious kernel module to trigger the faulty free path, a scenario that is inferred from the description and likely attack vector.
OpenCVE Enrichment
Debian DLA
Debian DSA