Impact
The Linux kernel DRM OMAP DSI driver previously created a copy of its interrupt service routine table to enable the unregistration of interrupts. Because the copied table referenced stack‑allocated objects used by the ISRs, an IRQ could be unregistered while an ISR was still executing; if the stack objects were freed in that window, a use‑after‑free condition would arise. This kernel memory corruption could lead to a kernel panic or give a local attacker the ability to execute arbitrary code with elevated privileges.
Affected Systems
All Linux kernel releases containing the DRM OMAP DSI driver before the patch that removes the ISR table copy are affected. The vulnerability applies to generic Linux systems running the kernel, with no specific vendor or version range limits beyond the inclusion of the affected driver.
Risk and Exploitability
The CVSS score of 7.8 classifies this flaw as high severity, while the EPSS score of less than 1% suggests a very low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector is a local user with sufficient privileges to manipulate IRQ registration, such as a system administrator or compromised privileged process, triggering the fault during ongoing ISR activity.
OpenCVE Enrichment
Debian DLA
Debian DSA