Impact
A buffer overflow exists in the Linux kernel IIO chemical driver for the mhz19b sensor. When the driver receives a serial reply, it appends each chunk into a fixed-size buffer without verifying that the chunk fits within the remaining space. This allows an oversized reply to overwrite the buffer, potentially corrupting kernel memory. The flaw could enable an attacker to execute arbitrary code with kernel privileges or subvert system integrity.
Affected Systems
All Linux kernel builds prior to the patch that adds reply‑size validation are affected. This applies to every distribution shipping the default kernel without the fix.
Risk and Exploitability
The EPSS score is below 1 %, indicating a low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would likely need local physical or logical access to the serial interface used by the mhz19b sensor, though the lack of remote exposure does not eliminate the risk of privilege escalation or denial of service on a compromised system.
OpenCVE Enrichment
Ubuntu USN