Impact
This kernel vulnerability arises when the ipack ioctl Octal device is removed while a tty session remains open. The removal callback releases an ipoctal structure that still may be accessed by active tty operations, causing a use‑after‑free. Additional paths lead to a null pointer dereference when the device removes its transmit buffer while a user process can write to the tty and to a second use‑after‑free when cleanup accesses a freed device pointer. The errors can trigger a kernel crash, yielding denial of service, and may be leveraged by an authenticated local user to execute arbitrary code at kernel privilege.
Affected Systems
Affected vendors: Linux for the Linux kernel. All kernel versions before the patch roll‑in fix the bug; exact version ranges are not listed in the data. Systems running any kernel whose source includes the obsolete ipoctal removal logic are vulnerable.
Risk and Exploitability
The simplified EPSS score of less than 1% indicates a very low probability of exploitation, and the exploit is not yet listed in CISA’s KEV catalog. The attack vector is local, requiring the attacker to trigger device removal while a tty session is active. Privilege escalation is possible if kernel memory can be overwritten. The impact score is high due to the potential for kernel panic, but the likely exploitability is low.
OpenCVE Enrichment
Debian DLA
Debian DSA