A flaw was found in the Nosy driver in the Linux kernel in versions prior to v5.12-rc6. It allows a device to be inserted twice into a doubly linked list, leading to use-after-free when one of these devices is removed.
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1948046]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
This was fixed for Fedora with the 5.11.12 stable kernel updates.