Linux Kernel Octeon EP Driver Use-After-Free Vulnerability in Error Path

Vulnerability

A use-after-free vulnerability has been identified in the Linux kernel Octeon EP driver. This issue arises when the `octep_probe` function fails to retrieve the device's MAC address, causing it to exit while leaving the delayed work `intr_poll_task` queued. When this queued work eventually executes, it leads to a use-after-free condition. The vulnerability affects the Linux kernel stable tree.

Impact

Exploitation of this vulnerability causes a use-after-free condition, which can lead to memory corruption and potentially allow for arbitrary code execution.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for upgrading the Linux kernel can be found in the official Linux documentation.

Added: Oct 7, 2025, 5:42 PM
Updated: Oct 7, 2025, 5:42 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
7.7
relevance
0.7
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.