Impact
The Mediatek pinctrl driver allocates the gpio_chip structure with device‑managed memory yet registers it using the non‑managed function gpiochip_add_data(). When the driver is unloaded as a module, the device‑managed memory is freed while the GPIO chip remains registered, leading to a use‑after‑free condition that can cause a kernel crash or memory corruption.
Affected Systems
The flaw exists in any Linux kernel that bundles the Mediatek pinctrl driver for Mediatek SoCs. Because no kernel version range is specified, all kernels before the applied patch could be impacted.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low exploitation probability. The attack vector requires the ability to unload or reload the affected module, a capability that is typically restricted to privileged users; this inference is made from the description that drivers can be built as modules and unbound. The primary risk is a kernel crash, and memory corruption could potentially lead to more severe outcomes if an attacker is able to exploit the use‑after‑free.
OpenCVE Enrichment