Impact
The Linux kernel contains a use‑after‑free flaw that occurs when a PCI device probe runs concurrently with the removal of a dynamic ID. The bug is caused by dynamic IDs being freed while still referenced in pci_match_device unless dynids.lock is held. An attacker who can influence the order of probing could trigger the freed memory to be accessed, leading to memory corruption or execution of malicious code within the kernel, potentially allowing local privilege escalation or denial of service.
Affected Systems
All versions of the Linux kernel that do not include the recent patch are affected. No specific version range is listed, meaning any kernel image prior to the fix is vulnerable.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a very low projected exploitation likelihood at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog, and no public exploit has been documented. The attack requires a local vector, typically through crafted PCI device enrollment during system initialization or device hot‑plug events, and therefore would likely be limited to systems where the attacker can introduce or manipulate PCI hardware. Based on the description, it is inferred that an attacker would need local access or the ability to control the PCI probing process to exploit this flaw.
OpenCVE Enrichment