Linux Kernel SCPI Firmware Probe Failure Use-After-Free Vulnerability

Vulnerability

A use-after-free vulnerability has been identified in the Linux kernel's SCPI (System Control and Power Interface) firmware handling. This issue arises because the SCPI information is not properly managed when the probing process fails. If the probe encounters an error, the SCPI information should remain null until a successful probe occurs. Failure to address this can lead to a use-after-free situation, as the SCPI operations could reference memory that was allocated but subsequently freed when the probe failed.

Impact

Exploitation of this vulnerability could lead to a use-after-free condition, potentially allowing for memory corruption or arbitrary code execution.

Added: Jun 18, 2025, 5:48 PM
Updated: Jun 18, 2025, 5:48 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
10.0
exploitability
4.0
remediation
0.0
relevance
0.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.