Impact
The vulnerability is a double decrement of a reference count when a phy device fails to be created. This double of_node_put leads to a double free of a device‑tree node object, which in a kernel context can corrupt memory and possibly enable arbitrary code execution or cause a crash. The bug occurs during the error path of devm_phy_create() in the Renesas rcar‑gen2 phy driver. The fix removes the redundant of_node_put so the scoped cleanup handles the release.
Affected Systems
Affected systems are Linux kernel installations that include the Renesas rcar‑gen2 PHY driver. The exact kernel releases are not listed, but any kernel that uses the rcar‑gen2 driver prior to the commit removing the double free is vulnerable. All Linux distributions that ship such kernels with this driver are impacted until they apply the kernel patch. The vendor list shows Linux by Linux, indicating the vulnerability is in the core kernel code.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity for a kernel memory‑corruption bug. The EPSS score is less than 1 %, showing the likelihood of exploitation is very low under current exposure data. The vulnerability is NOT listed in CISA’s KEV catalog. An attacker would likely need local or remote code that can execute privileged kernel code, such as manipulating device tree data, enabling the faulty driver, or exploiting a boot‑time scenario. Since the bug is a double free, the exploit could cause a denial of service or, if leveraged, may lead to privilege escalation. The attack vector is inferred as local and requires the ability to influence the device tree or kernel module loading path.
OpenCVE Enrichment