Impact
The kernel’s firmware_loader subsystem contains a race condition where a completed sysfs fallback request can be added twice to the pending list. A userspace helper that writes to the "loading" attribute can trigger a use‑after‑free, causing the kernel to dereference freed memory during list validation. The flaw does not provide direct code execution but can corrupt kernel memory, potentially leading to a crash or exploitation of other kernel vulnerabilities to gain higher privileges.
Affected Systems
All versions of the Linux kernel released before the corresponding patch are affected. The vulnerability is present at the kernel level and applies to every distribution that ships the unpatched kernel in its default configuration.
Risk and Exploitability
The EPSS score is less than 1% and the flaw is not listed in the CISA KEV catalog, indicating a very low likelihood of widespread exploitation. However, because the flaw is a local use‑after‑free in a privileged subsystem, a local attacker with write access to /sys/class/firmware_loading can trigger the race condition. If the attacker can also trigger a subsequent vulnerability that is dependent on corrupted memory, privilege escalation or denial of service could result. The attack vector is local system access; remote exploitation is not supported by the current description.
OpenCVE Enrichment
Debian DLA
Debian DSA