Linux Kernel QCOM EDAC Driver Use-After-Free Vulnerability

Vulnerability

A use-after-free vulnerability has been identified in the Linux kernel's QCOM EDAC driver. The issue arises because the driver improperly manages memory for private driver information. Specifically, the LLCC driver allocates memory that is then passed to the EDAC core as private info. When the QCOM EDAC driver is released, this memory is freed. If the driver is probed again, it attempts to use the freed memory, leading to the use-after-free condition.

Impact

Exploitation of this vulnerability can lead to a use-after-free condition, which may be exploited to execute arbitrary code or cause a denial-of-service condition by crashing the system.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
7.9
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.