Impact
The vulnerability is a Use‑After‑Free (CWE-364) that occurs when the USB driver performs a probe operation concurrently with the removal of a dynamic USB ID. A node that has been freed can still be accessed, allowing an attacker to corrupt memory or crash the kernel. The change fixes this by making a copy of the ID during probe and clarifying that the ID parameter is only valid during the probe operation.
Affected Systems
All Linux kernel builds are potentially affected until the patch is deployed. The vendor listing identifies Linux:Linux; versions are not specified in the CNA data, so the vulnerability may exist in any kernel revision lacking this fix.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, a local attacker with USB access can trigger the flaw by connecting a crafted USB device while a device with a dynamic ID is undergoing removal. Successful exploitation could lead to a denial‑of‑service crash or possible privilege escalation, depending on system configuration. The CVSS severity is not explicitly stated, but the use‑after‑free nature suggests a potential high impact if leveraged.
OpenCVE Enrichment
Debian DLA
Debian DSA