Impact
The remoteproc subsystem in the Linux kernel lacks proper synchronization between crash‑handler work and driver removal. This allows a driver to be freed while crash‑handler work is still scheduled or executing, resulting in a use‑after‑free condition that can corrupt kernel memory and provide an opportunity for a local attacker to execute arbitrary code with kernel privileges.
Affected Systems
All Linux kernel releases that compile and run the remoteproc subsystem and have not yet incorporated the patch that introduces a deleting flag to cancel pending crash‑handler work. Because no specific version numbers are provided, any kernel containing the vulnerable code before the fix is considered at risk.
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation (<1%) and the vulnerability is not listed in CISA’s KEV catalog, implying no public exploits are known. However, the flaw can lead to kernel privilege escalation if an attacker can trigger the use‑after‑free, which would typically require local kernel access or the ability to initiate driver removal. Consequently, the overall risk is moderate for systems that load vulnerable remoteproc drivers without the patch.
OpenCVE Enrichment
Debian DLA
Debian DSA