Executive brief
A vulnerability in the Linux kernel's Intel Vision Sensing Controller (IVSC) driver can cause a system crash during shutdown. This issue occurs because the system fails to properly clean up internal communication components, leading to memory corruption. While primarily affecting system stability and availability, such flaws can sometimes be leveraged by local attackers to gain unauthorized control over the system.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's Intel Vision Sensing Controller (IVSC) driver within the ACE and CSI submodules. The root cause is a missing call to mei_cldev_disable() in the remove() functions of these drivers. Consequently, the mei_cl client remains in the mei_device->file_list even after its memory is freed by mei_cl_bus_dev_release(). When mei_vsc_remove() subsequently calls mei_stop() and mei_cl_all_disconnect(), the kernel attempts to dereference the already-freed memory. This can be triggered during system shutdown or manual driver removal. Patches have been released for various stable kernel branches including 6.6.y, 6.12.y, and 6.16.y.
Affected products
- Linux Linux Kernel 6.6 to 6.6.103, 6.12 to 6.12.44, 6.16 to 6.16.4
Timeline
- 2025-06-21: patched: Initial patch authored by Hans de Goede
- 2025-09-05: disclosed: CVE published