Impact
A use‑after‑free flaw exists in the Linux USB Type‑C PMI driver: when a port is stopped, delayed work can be queued after the port resource has been freed, allowing the work to execute on invalid kernel memory. This can corrupt kernel memory and potentially lead to kernel‑level code execution.
Affected Systems
The vulnerability affects Linux kernel builds that include the qcom‑pmic‑typec USB Type‑C driver. Version information is not specified, so any affected build prior to the patch may be at risk. The specific kernel releases and patches that mitigate the issue are not publicly listed at this time.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity flaw. Because the EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, the probability of exploitation is low at present. Based on the description, it is inferred that an attacker would need to initiate a USB device interaction before the driver stops to trigger the delayed work path. Local attackers who can control USB devices may exploit this dangling pointer, potentially achieving privilege escalation to kernel mode.
OpenCVE Enrichment
Debian DLA
Debian DSA