Impact
The vulnerability is in the Linux kernel DRM subsystem for Rockchip SoCs. In dw_dp_bind, core resources such as the DisplayPort AUX channel are allocated and registered, but the corresponding cleanup code was omitted. This oversight can cause memory leaks and a kernel use‑after‑free, leading to kernel memory corruption and system instability or a crash. The flaw is a classic resource‑management bug that may be exploitable if an attacker can trigger a driver bind or unbind sequence.
Affected Systems
Any Linux kernel that includes the dw_dp and rockchipdrm DRM modules prior to the fix is affected. The distribution vendor is Linux, and vendor product is the generic Linux kernel. No specific version numbers are provided; any kernel version before the merge that introduced dw_dp_unbind cleanup is potentially vulnerable.
Risk and Exploitability
The EPSS score of < 1 % indicates a low likelihood of active exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker with local access could load or unload the driver to trigger the bug, which could result in a kernel memory corruption and potentially cause a denial of service. Exploitation would require local code execution capabilities; no remote vector is described.
OpenCVE Enrichment