Impact
The rapidio driver in the Linux kernel stores a newly allocated rio_net in mport->net before registering the device. If rio_add_net() fails, the device reference is released, but mport->net continues to point at the freed object. A later mport unregister path can dereference this dangling pointer and attempt to free the same rio_net again, resulting in a use‑after‑free that can crash the kernel and cause denial of service. This flaw primarily impacts availability; the advisory does not indicate that privilege escalation is possible.
Affected Systems
All Linux kernel releases that include the rapidio driver without the patch identified in the referenced commits. The specific vendor is Linux and the product is the Linux Kernel; version information is not explicitly provided in the advisory, implying that any kernel prior to the fix is affected.
Risk and Exploitability
The EPSS score is under 1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The bug is a kernel use‑after‑free; an attacker would need local system access to trigger the failure and subsequent unregistration. Because the flaw lives in kernel space, the most likely impact is a system crash or denial of service. The overall risk is low to moderate and is chiefly local.
OpenCVE Enrichment
Debian DLA
Debian DSA