Impact
The Linux kernel’s USB Type‑C driver for Qualcomm PMIC devices contains a race condition where the PHY stop routine disables interrupts but leaves a pending reset_work unfinished. If the interrupt handler schedules this work just before interrupts are disabled, the work executes after the driver’s device structure has been freed by the device removal code. This results in a use‑after‑free condition that can crash the kernel or, if triggered by an attacker, lead to privilege escalation. The weakness is a classic use‑after‑free flaw, corresponding to CWE‑416.
Affected Systems
This defect is confined to the Linux kernel itself, affecting any build that includes the qcom_pmic USB Type‑C driver in the kernel tree. It is not tied to a particular vendor product or kernel release beyond the presence of the driver, so any kernel that contains the affected code and uses devm‑managed resources is exposed.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity issue, while the EPSS score below 1% suggests that exploitation is currently unlikely. Although the flaw is not listed in the CISA KEV catalog, the window can be exploited because the use‑after‑free occurs after the relevant structure is freed. An attacker would need to trigger the race condition, but if successful, could cause arbitrary code execution with kernel privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA