Impact
On DSI 6G platforms the snapshot logic in the Linux DRM MSM DSI driver fails to reduce the control size by the io_offset value after adjusting the IO address space. This oversight can result in a memory dump that extends beyond the mapped region, exposing or corrupting kernel memory. The vulnerability is a CWE‑131 incorrect size calculation flaw that may lead to both information disclosure and system instability.
Affected Systems
All Linux kernel builds that incorporate the MSM DSI 6G driver and compile the msm_disp_snapshot functions are affected. The flaw exists in any kernel which contains the unpatched snapshot code on devices that use the MSM display driver; no particular release is specified, so any kernel with these components and not yet amended is vulnerable.
Risk and Exploitability
The EPSS score of < 1 % and absence from the CISA KEV catalog indicate a low but non‑zero likelihood of exploitation. Based on the description, the likely attack vector is a local privileged process that invokes the snapshot routines. The flaw requires local privileged access, making it a local‑exploit vulnerability. No public exploit is known, but successful exploitation could leak kernel memory and potentially destabilize the system.
OpenCVE Enrichment
Ubuntu USN