Impact
The bug arises in the v4l2_async subsystem when an em28xx USB device that uses the tvp5150 I2C driver is disconnected. Because the em28xx driver does not support v4l2_async, an empty asc_list remains. Consequently, v4l2_async_unregister_subdev never calls v4l2_device_unregister_subdev, causing the driver to attempt to unregister a sub‑device that has already been removed. This sequence leads to a kernel crash and a local denial of service on the affected system.
Affected Systems
Vendor: Linux. The affected product is the Linux kernel; any version that has not yet incorporated the described fix is potentially vulnerable. The issue was observed with the em28xx USB driver and tvp5150 I2C module. The CPE string indicates that the problem is relevant to all Linux kernel releases until the mitigation is applied.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. The attack scenario inferred from the description requires the attacker to cause the device to be detached or to trigger the unregister path, which typically demands local or privileged access to the USB subsystem. Based on the explanation, the most plausible vector is local with physical or administrative control of the target machine, making a network‑based remote exploit unlikely.
OpenCVE Enrichment
Debian DLA
Debian DSA