Impact
In the Linux kernel’s UIO subsystem, a device becomes visible to userspace after device_add() but before the registration process completes. If a later initialization step fails, the unwind logic removes the device yet leaves idev->info pointing to a caller‑owned struct uio_info. An orphaned open file descriptor that holds a reference to the uio_device can race with the failure path; when the caller frees uio_info, subsequent file operations dereference the now‑dangling pointer, producing a use‑after‑free bug that can corrupt kernel memory; based on the description, it is inferred that this could allow arbitrary code execution, though the description does not state this conclusively.
Affected Systems
All Linux kernel versions that do not yet incorporate the commit which clears the stale uio_info pointer are affected. This includes every distribution kernel lacking the patch and any custom UIO driver that registers a device via device_add and fails during initialization without performing the proper cleanup.
Risk and Exploitability
The CVSS score of 7.0 indicates moderate to high severity, while the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would require the ability to register a UIO device and to coordinate a race between opening /dev/uioX and the failure cleanup. This capability typically implies local privileged access to load a kernel module or similar privilege; this inference is noted because the description does not explicitly state the attacker model.
OpenCVE Enrichment
Debian DLA
Debian DSA