Impact
This vulnerability is a race condition that can cause a device reference to be released twice, freeing a struct hid_device while it is still in use. The result is a use‑after‑free that an attacker could exploit to crash the system or execute arbitrary code.
Affected Systems
Affected products include the Linux kernel on all distributions that have not yet applied the fix that serializes device reference release. The specific versions are not listed, but any kernel containing the insecure bpf/ HID paths is vulnerable.
Risk and Exploitability
With a CVSS score of 7.8 this issue is considered high severity. The EPSS score is below 1%, indicating low current exploitation likelihood, and it is not listed in the CISA KEV catalog. Exploitation would require a local or elevated attacker who can race hid_bpf_ops_destroy_device and hid_bpf_unreg, so physical or administrative access would be needed.
OpenCVE Enrichment
Debian DLA
Debian DSA