Impact
A use‑after‑free flaw exists in the a6xx_gpu_init function of the drm/msm/adreno DRM driver. When the initialization fails, the driver frees the a6xx_gpu structure while the adreno_gpu pointer still references the now‑freed memory. If an attacker can exercise this error path before the memory is reused, the dangling pointer may be used to read or overwrite data in the freed area, leading to kernel memory corruption that could crash the system or serve as a foothold for privilege escalation. The weakness is identified as CWE‑416.
Affected Systems
The vulnerability affects Linux kernel installations that include the Adreno DRM driver for Adreno GPUs, specifically the drm/msm/adreno module. All kernel builds that contain the a6xx_gpu_init initialization logic are potentially affected; no specific version range is given in the advisory.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low likelihood of exploitation as of this analysis. The vulnerability is not listed in CISA KEV, and no active exploitation has been documented. The attack would likely require local or privileged access to trigger the driver’s error path during GPU initialization. The use‑after‑free can cause kernel memory corruption and, if an attacker can influence the contents of the freed memory, could lead to arbitrary kernel code execution. However, the practical difficulty of exploiting this path keeps the immediate risk moderate to high in potential impact but low in expected exploitation probability.
OpenCVE Enrichment