Impact
The Linux kernel UBI subsystem contains a reference‑counting bug in ubi_detach_mtd_dev(). The function obtains a device reference before verifying that the UBI device is idle. If the device is busy, it returns EBUSY after decrementing the UBI ref count but fails to release the held device reference, leaving the device object unreleasable on subsequent detach attempts. This results in a resource leak that can prevent the device from being properly removed and may exhaust kernel storage for device objects.
Affected Systems
All Linux kernels that include the buggy ubi_detach_mtd_dev implementation are affected. The bug resides in the ubi driver, so any system with UBI support compiled into or loaded as a module (common in embedded Linux devices using flash storage) is potentially impacted. No specific kernel versions are listed; the flaw applies to every build that contains the unpatched ubi code.
Risk and Exploitability
The EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no CVSS score is provided. The CVE description does not describe a remote attack surface or required privilege level; therefore, exploitation would likely be possible only through legitimate calls to ubi_detach_mtd_dev, typically performed by system utilities or kernel components with local access. The resulting denial of service originates from a resource leak that can prevent a busy UBI device from being fully detached or reused.
OpenCVE Enrichment
Debian DLA
Debian DSA