Impact
The vulnerability is a use‑after‑free condition in the Linux kernel HID subsystem. During a Sony controller probe, the driver registers the device, and if input registration fails then the hardware cleanup is performed but the list node remains linked to freed memory. This leaves a dangling list entry that can be dereferenced by a subsequent controller match, potentially causing a kernel crash or arbitrary code execution.
Affected Systems
All Linux kernels that include the Sony HID driver code before the applied patch are affected. The vulnerability exists in the generic Linux kernel implementation of the HID subsystem and therefore applies to all major distributions that ship a stock kernel with the Sony driver.
Risk and Exploitability
The CVSS base score of 8.8 indicates high severity if exploited. EPSS <1% and absence from KEV suggest a low likelihood of current exploitation or exploitation not yet observed. No publicly available exploits are documented in the CVE data. Exploitation would require triggering a Sony controller probe resulting in input registration failure and the associated use‑after‑free, potentially leading to a kernel panic or code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA