Impact
The vulnerability is a heap-based buffer overflow in Intel(R) Open Volume Kernel Library (Open VKL) before version 2.0.2 that can be triggered from user mode. Failure to contain the overflow can corrupt internal data structures and cause the library to crash, leading to a denial of service of the application or system that depends on it. The flaw does not directly expose confidential data, but it can reduce integrity by corrupting memory and availability by crashing the affected process.
Affected Systems
Intel Open VKL versions earlier than 2.0.2 are affected. The issue is present in the library code exploited by user-space applications on systems that use the Open VKL API. The vendor is Intel; no additional product names were specified beyond the library.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high risk, and the EPSS score of less than 1% suggests that exploitation is unlikely but still possible. The flaw is not listed in the CISA KEV catalogue. Attack conditions require an authenticated local user and low complexity effort; no special knowledge or active user interaction is needed. An authenticated attacker with local access can invoke the library through a vulnerable application, causing a crash that results in service disruption.
OpenCVE Enrichment