Impact
The vulnerability in the Linux kernel arises from an incorrect ordering of pointer initialization within the OPP subsystem. During cleanup, the function _opp_kref_release attempts to access opp->opp_table after opp has already been freed, producing a use‑after‑free condition. This flaw can allow an attacker that can trigger the cleanup process to overwrite or read corrupted memory, potentially leading to arbitrary code execution or denial of service within kernel mode.
Affected Systems
All Linux kernel implementations prior to the inclusion of commit 173e02d67494 in this subsystem are vulnerable. The affected product is the Linux kernel; no specific version range is enumerated, so any kernel revision that omits this commit must be considered at risk.
Risk and Exploitability
The EPSS value is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of active exploitation. Without a published CVSS score, the severity is known only from the nature of the flaw—use‑after‑free—suggesting that if exploited, the impact could be high. The attack mainly requires kernel‑mode access or a way to force the module to unload and trigger the cleanup sequence; this is inferred from the description of the flaw and is not explicitly confirmed. The attacker would need the ability to influence the lifecycle of OPP resources to provoke the fault.
OpenCVE Enrichment