Impact
A buffer under‑read in the lpp‑vita library allows an attacker to read data beyond the bounds of an allocated memory region. The flaw is identified as CWE‑125 and can lead to disclosure of adjacent memory contents, which may contain sensitive information depending on the runtime environment. No evidence is provided that the flaw enables code execution or denial of service; the impact is limited to potential information leakage.
Affected Systems
This vulnerability affects Rinnegatamante’s lpp‑vita library versions prior to revision 6. The impacted software is the lpp‑vita component used in media or gaming applications, identified by the vendor name Rinnegatamante and product lpp‑vita.
Risk and Exploitability
The CVSS score of 7.8 classifies it as high severity, yet the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The most probable attack vector is local – an attacker who can execute or influence the lpp‑vita code may trigger the out‑of‑bounds read, but remote exploitation is not documented in the provided information.
OpenCVE Enrichment