Impact
The vulnerability is a type‑confusion flaw in the Zephyr HL78xx GNSS NMEA driver that causes the kernel parser to write parsed data to a location that is determined by an uninitialized, wild pointer. The mismatch in struct layout results in writes to an incorrect memory region, potentially corrupting kernel memory or causing a crash. The flaw does not or, on MMU-less targets, possible memory corruption.
Affected Systems
Any Zephyr build that includes the HL78xx modem GNSS driver (drivers/modem/hl78xx/) and uses the default GNSS source (CONFIG_HL78XX_GNSS_SOURCE_NMEA) is affected. The issue is present in all releases that contain the buggy layout before the commit 8a2465784e8909aa3835559381a60c00cc2218a1. No specific product version numbers are provided, so all builds that have not applied this patch are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate impact. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting low to moderate exploitation probability. An attacker would need to spoof GNSS signals in proximity to the device and requires the satellite parsing feature (CONFIG_GNSS_SATELLITES) to be enabled, making the attack complexity high. The primary consequence is a kernel crash that could lead to denial of service.
OpenCVE Enrichment