Impact
The kernel defect occurs when sysfs attribute callbacks for an I3C master controller access the master->this structure after it has been freed by i3c_master_detach_free_devs. Because master->this is dereferenced after its memory has been released, a dangling pointer is used, which can corrupt memory and potentially allow an attacker to execute arbitrary code at the kernel level. This is a classic Use‑After‑Free flaw and directly compromises the integrity and confidentiality of the system.
Affected Systems
The vulnerability affects the Linux kernel wherever the I3C master controller subsystem is present. Affected versions are not enumerated, so every kernel build that includes the unpatched I3C master code is potentially vulnerable. The issue is associated with the Linux vendor.
Risk and Exploitability
The EPSS score of less than 1% indicates that the defect has an extremely low probability of being exploited in the wild at the current time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Because a use‑after‑free can lead to arbitrary kernel code execution, the potential impact is high if an attacker can trigger the vulnerable sysfs path. Inferred attack vectors suggest a local or privileged user could trigger the flaw through sysfs interaction, though the exact prerequisites are not detailed in the advisory. The lack of a CVSS score in the provided data means the community has not yet quantified the severity, but the nature of the flaw suggests severe risk if exploited.
OpenCVE Enrichment