Impact
The vulnerability is a race condition in the Linux kernel Dell privacy module on x86, where the structure priv->features_present is accessed without holding the list mutex. This allows a privileged user to free the priv object while it is still being accessed, leading to a use‑after‑free that can crash the kernel or enable execution of arbitrary code in kernel mode. The weakness is identified as a race condition (CWE-362) and a use‑after‑free (CWE-416).
Affected Systems
All Linux kernel releases that contain the vulnerable code and have not yet incorporated the fix commit (239ae86b7c97341f49d2ba32037ee3ddbaf0f1ab or later). The exact affected kernel versions are not enumerated in the data, but any distribution shipping a kernel prior to the patch should be considered vulnerable.
Risk and Exploitability
The EPSS score is below 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. No public exploit has been documented. However, because the flaw can lead to kernel privilege escalation or denial of service, the risk remains high if an attacker obtains local or root access. Based on the description, it is inferred that the exploit requires local or root access. The CVSS score is not defined in the provided data, but the nature of the bug suggests a high impact should it be exploited locally.
OpenCVE Enrichment
Debian DLA
Debian DSA