Impact
The vulnerability arises because the ioctl handlers for the mtip32xx block driver only check a pending‑removal flag before calling the core ioctl routine. When a device removal occurs, the flag can be set immediately afterwards and the device’s private data may be freed while an ioctl is still in progress, permitting the handler to dereference freed memory. This use‑after‑free can corrupt kernel memory and potentially allow an attacker with local access to execute arbitrary kernel code or cause a denial of service.
Affected Systems
All Linux kernel systems that load the mtip32xx block driver are affected. The vulnerability exists in kernel versions before the commit that synchronizes IOCTLs with device removal; specific affected versions are not listed.
Risk and Exploitability
The EPSS score of less than 1 % indicates the likelihood of exploitation is currently very low, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is not provided, but the use‑after‑free flaw suggests a high severity if exploited. Attackers would need local or privileged access to perform the vulnerable ioctl while the device is being removed, making this a local‑scope risk.
OpenCVE Enrichment
Debian DLA
Debian DSA