Impact
An integer underflow in the STMMAC network driver’s jumbo frame handling creates an enormous length value that causes the DMA engine to map memory far beyond the intended buffer. This results in a kernel memory disclosure and potentially kernel memory corruption, exposing sensitive data and jeopardizing system integrity. The flaw is related to CWE‑190 (Integer Overflow or Underflow).
Affected Systems
All Linux kernel installations that include the STMMAC driver before the patch, particularly on SoCs that lack an IOMMU. The vulnerability is present in any kernel version up to the most recent stable releases that have not yet incorporated the commit that fixes the underflow.
Risk and Exploitability
With a CVSS score of 9.8, the vulnerability is considered critical. The EPSS score is below 1 %, indicating a low current exploitation probability, but the high impact warrants prompt action. Based on the description, the likely attack vector is sending specially crafted Ethernet frames to the affected interface, allowing an attacker with network access—local or remote—to trigger the underflow and read kernel memory. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA