Impact
The vulnerability arises when the USB serial driver for digi_acceleport accepts a malicious device that reports bulk‑out buffer sizes smaller than expected. Because the driver fails to perform size sanity checks, it can write beyond the allocated buffer and corrupt kernel memory, potentially allowing an attacker to execute arbitrary code with kernel privileges. This is a buffer overrun (CWE‑787) vulnerability.
Affected Systems
All Linux kernel releases that include the digi_acceleport serial driver are impacted. The exact kernel version is not specified in the advisory, so any system running a kernel that has not yet incorporated the patch is vulnerable.
Risk and Exploitability
The CVSS score is 7.0. The EPSS score indicates a probability of exploitation below 1%, which is very low. Based on the description, it is inferred that exploitation requires a USB device that reports smaller buffers than expected, meaning the attacker needs physical or remote to attach a malicious peripheral and may be possible from a local or remote USB interface. The vulnerability is not currently listed in CISA KEV, suggesting no known widespread exploitation, but the potential impact remains significant if an attacker gains local access.
OpenCVE Enrichment
Ubuntu USN