Impact
The kernel driver for ACPI PCI roots does not clear its driver_data pointer when a root is freed, leaving a dangling reference. If an add or removal operation fails, the pointer remains set and later calls to acpi_pci_find_root may dereference it. This use‑after‑free can corrupt kernel memory or lead to arbitrary code execution with kernel privileges, effectively creating a serious kernel exploitation vector.
Affected Systems
All Linux kernel builds that have not incorporated the commits referenced in the matrix. The CPE indicates applicability to every version of the Linux kernel, and no specific version range is provided, so any system with the vulnerable kernel is potentially impacted.
Risk and Exploitability
The EPSS score is below 1% and the CVE is not listed in the CISA KEV catalogue, suggesting low observed exploitation activity. Nevertheless, the exploitation of a kernel use‑after‑free remains a high‑severity risk: a local or firmware‑based attacker could trigger ACPI hot‑add or removal paths to create the dangling pointer and then use defined memory corruption techniques to gain kernel privileges. The vulnerability is classified under CWE‑416.
OpenCVE Enrichment
Debian DLA
Debian DSA