Impact
The keyspan USB serial driver in the Linux kernel lacked a sanity check on the size of usa49wg indat transfers, which caused the driver to parse potentially stale or uninitialized slab data. This flaw can lead to kernel memory corruption, potentially resulting in a kernel panic or other integrity violations. The vulnerability presents a moderate severity risk as reflected by the CVSS score of 5.5.
Affected Systems
All Linux kernel builds that include the keyspan USB serial driver and have not yet incorporated the fix commits are vulnerable. Any system that loads the keyspan module and receives data from a keyspan USB device is exposed until the kernel is updated.
Risk and Exploitability
The EPSS score is below 1 %, and the vulnerability is not listed in CISA KEV, indicating a low exploitation probability under current conditions. An attacker would need to provide a specially crafted USB keyspan device to trigger the driver. While no public exploits are currently known, the moderate CVSS score and memory corruption potential could allow a successful exploitation to cause denial of service or, under certain circumstances, further compromise.
OpenCVE Enrichment
Ubuntu USN