Impact
During binding the DisplayPort AUX channel is initialized and registered, but the corresponding unbind routine was omitted. The missing cleanup can lead to resource leaks and, more critically, a use‑after‑free in the kernel. An attacker who can cause the driver to reference freed memory may execute arbitrary code with kernel privileges. The weakness is characteristic of improper resource management and use‑after‑free vulnerabilities (CWE‑416, CWE‑401).
Affected Systems
The flaw is present in the Linux kernel, affecting all distributions that ship the unpatched kernel code. No specific version range is listed, so any kernel containing the obsolete dw_dp_bind implementation without a matching dw_dp_unbind is potentially vulnerable. This includes standard production kernels as well as custom builds that use the Synopsys DisplayPort driver.
Risk and Exploitability
The EPSS score is below 1 % and the issue has not been catalogued by CISA as a known exploited vulnerability, indicating a low current exploitation probability. Nonetheless, the high severity of a kernel use‑after‑free, combined with local or privileged code execution potential, gives the vulnerability a high severity rating. Attackers would need to gain local access to send crafted requests to the DisplayPort subsystem or to trigger a path that forces the use of a dangling AUX channel reference. The vulnerability is likely exploitable only within the local machine context but can result in full system compromise.
OpenCVE Enrichment