Impact
The Linux kernel bug allows a console use‑after‑free when a legacy printing handover occurs while a console buffer is still in use. After the handover the console SRCU read lock is released, the console struct pointer may become invalid, and subsequent access can dereference freed memory. This flaw can lead to memory corruption or a system crash.
Affected Systems
The vulnerability resides in the Linux kernel itself and affects any system that uses the legacy console printing infrastructure. No specific kernel versions are listed in the CNA information, so the issue may exist across multiple releases until the patch is applied.
Risk and Exploitability
The EPSS score for this vulnerability is below 1%, indicating a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not part of known actively exploited vulnerabilities. Therefore, the overall risk assessment is low, though environments that rely on legacy console printing remain vulnerable to a use‑after‑free that could cause memory corruption or a system crash once the handover occurs.
OpenCVE Enrichment
Debian DLA
Debian DSA