Impact
The vulnerability arises from a use‑after‑free condition in the Realtek CR USB storage driver of the Linux kernel. During device disconnection, the destructor calls timer_delete on a timer object that has not yet completed its callback. The timer callback may still be executing and can rearm itself, leading to a use‑after‑free. This flaw provides an available vector for arbitrary code execution or memory corruption when an attacker can trigger the disconnect sequence.
Affected Systems
All Linux kernel deployments that include the Realtek CR USB storage driver before the patch. The CPE indicates the general Linux kernel, so any distribution using a kernel version with the unpatched driver is potentially affected. No specific version ranges were given, so it is assumed all current kernels are impacted until the commit is merged.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, a use‑after‑free is a high‑severity weakness that can lead to privilege escalation or denial of service. Inference suggests that the attack requires the ability to manipulate a Realtek CR USB device or send a crafted disconnect notification; local privileged users could exploit it, and a remote attacker might gain access if the device is exposed via a networked host that accepts USB attachments. No additional prerequisites are noted, so the primary limitation is the presence of the Realtek CR hardware and the ability to cause a breakpoint on disconnect.
OpenCVE Enrichment