Impact
In the Linux kernel media subsystem, the bcm2835-unicam driver allocates an asynchronous callback structure during device registration but never frees it when the module unloads or an error occurs. The unfreed structure persists in kernel memory, which the memory‑leak detector identifies as a leak. While this flaw does not enable direct, the leaked data may contain sensitive kernel information that could be read by a local attacker, potentially exposing confidential data or affecting system stability through memory pressure.
Affected Systems
All Linux kernel builds that include the bcm2835-unicam driver, typically found on devices using the BCM2835 SoC such as Raspberry Pi boards and other ARM-based embedded systems, are affected. The CVE does not list specific kernel versions, so any build lacking the upstream commit that releases the freed asc should be treated as vulnerable.
Risk and Exploitability
The EPSS score is below 1 %, and the vulnerability is not listed in CISA’s KEV catalog, implying a low likelihood of exploitation. Based on the description, it is inferred that an attacker would need local access or privileged execution to unload the driver or trigger the error path that causes the leak. No publicly documented remote attack vector exists, and the flaw does not enable arbitrary code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA