Impact
An infinite loop occurs in the Zephyr SDIO subsystem function sdio_io_rw_extended_helper() when the SDIO card reports a maximum block size of zero. The loop size calculation never reduces the remaining transfer size, causing the thread that performs the transfer to block indefinitely and to keep the per-card lock held. This permanently stalls all SDIO activity, including dependent subsystems such as Wi‑Fi, but does not affect data integrity or confidentiality.
Affected Systems
All Zephyr RTOS builds that include the SDIO subsystem and support removable SDIO card interfaces are affected, regardless of the specific Zephyr release version. The defect manifests when drivers invoke public SDIO client APIs such as sdio_read_fifo() or sdio_write_fifo().
Risk and Exploitability
The CVSS score is 4.6 and the EPSS score is less than 1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a specially crafted SDIO card that reports a zero block size; therefore the attack vector is physical insertion of a malicious or malfunctioning card into a removable SDIO/combo slot. Devices with soldered SDIO peripherals are not susceptible. The effect is a permanent loss of availability for the SDIO peripheral and dependent subsystems until the device is reset or the card is removed.
OpenCVE Enrichment