Impact
The Linux kernel media driver for ipu6 contains a double‑free flaw during bus initialization. After an auxiliary device is successfully added, the driver again frees the same data structure, corrupting kernel memory and causing a crash. The result is a denial of service to the affected system.
Affected Systems
The flaw exists in all versions of the Linux kernel that include the ipu6 media driver prior to the fix. No specific kernel releases are enumerated in the advisory, so any kernel containing this driver may be vulnerable.
Risk and Exploitability
Likely attack vector involves local or privileged access to the system to trigger the ipu6 driver’s bus initialization routine. Once initiated, the driver’s double‑free logic would corrupt kernel memory and cause a crash, resulting in denial of service. The CVSS score of 7.8 signals a serious denial‑of‑service risk, while the EPSS score of less than 1 % indicates low exploitation probability. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA