Impact
During module removal the debugfs entries and console log are torn down, but the notifier remains registered. If a kernel panic occurs after this removal, the notifier's callback will run against data that has already been freed. Based on the description, it is inferred that this freed data access could lead to arbitrary code execution or a system crash. This use‑after‑free flaw (CWE‑416) could compromise confidentiality, integrity, and availability of the host.
Affected Systems
Vendors are Linux kernel maintainers. It is inferred that the vulnerability affects any Linux kernel build that includes the cros_ec_debugfs module, such as Chrome OS releases that use the Chrome OS EC debug filesystem. Specific version numbers are not listed in the advisory; operators should verify if their kernel contains this module and the problematic init/exit logic.
Risk and Exploitability
The EPSS score is the lowest band (<1%) and the flaw is not cataloged in CISA KEV, indicating a low likelihood of widespread exploitation. Nonetheless, the impact of executing code during a kernel panic is severe, giving an attacker potential root‑level control, especially if they can trigger a panic (e.g., via malformed EC commands). The likely attack vector is local and requires the ability to cause a panic in the targeted system.
OpenCVE Enrichment
Debian DLA
Debian DSA