Linux Kernel Use-After-Free Vulnerability in FSI OCC Driver

Vulnerability

A use-after-free vulnerability has been addressed in the Linux kernel's FSI OCC driver. The issue arose because the device could be freed while a file descriptor was still open. The vulnerability affected several versions of the Linux kernel. The root cause was improper management of device references, which could lead to accessing freed memory. Exploitation of this vulnerability could potentially cause undefined behavior, such as accessing invalid memory or causing a system crash.

Impact

The vulnerability could lead to a use-after-free condition, allowing for potential memory corruption or exploitation of the freed memory.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version are available on the official Linux kernel website.

Added: Dec 30, 2025, 12:21 PM
Updated: Dec 30, 2025, 12:21 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
7.7
relevance
1.8
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.