Impact
The flaw occurs when tty_cdev_add() drops a reference to a character device but leaves the driver's internal array pointing to freed memory. When tty_unregister_device() later attempts to delete that stale pointer, a use‑after‑free is triggered inside the kernel, potentially corrupting memory. The resulting fault could crash the kernel, and based on typical use‑after‑free semantics, it is inferred that a locally privileged attacker who can influence the freed structure may be able to execute arbitrary code at kernel level, leading to privilege escalation.
Affected Systems
The vulnerability exists in the Linux kernel. All kernel builds that lack the patch are potentially affected; no specific version list is provided in the CVE data.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Although the CVSS score is not supplied, the kernel‑level use‑after‑free implies high severity. The likely attack vector involves a local attacker with the ability to load or manipulate tty drivers to trigger the fault.
OpenCVE Enrichment
Debian DLA
Debian DSA