Impact
The SC2731 charger driver in the Linux kernel fails to cancel pending work when the charger device is removed. The removal path unregisters the USB notifier while leaving queued or running work that references the driver’s data. When that data is freed, the work may execute on stale memory, creating a use‑after‑free condition (CWE‑416). This flaw can trigger kernel memory corruption, a panic, or potentially provide an attacker with a privilege escalation path if an exploit is crafted.
Affected Systems
All Linux kernel distributions that include the sc2731 charger driver module are affected. The issue remains present in currently released kernel versions until the patch is applied, affecting any device that supports SC2731 hardware: desktop laptops, embedded boards, or any system with this charger controller driver.
Risk and Exploitability
The EPSS score is below 1 %, indicating a low likelihood of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog, so no public exploits have been reported. Nonetheless, an attacker with local or limited physical access—such as a malicious USB power source or power‑cycle attack—could trigger charger removal and exercise the use‑after‑free. Because the flaw occurs at kernel privilege, successful exploitation could lead to complete system compromise. The lack of an explicit CVSS score means the impact is inferred from the kernel context and the nature of the defect, suggesting high severity if exploited.
OpenCVE Enrichment
Debian DLA
Debian DSA