Impact
The scd30 driver in the Linux kernel incorrectly applied a bit mask to a 32‑bit floating‑point value, causing sign‑extension errors that corrupted the exponent field. The resulting sensor readings are inaccurate, affecting any logic that relies on those values. The fault does not enable arbitrary code execution or direct system compromise, but it represents a data‑integrity problem that can mislead users or automated control systems.
Affected Systems
All Linux kernel deployments that include the iio:chemical:scd30 driver are affected. The issue existed before the commit that introduced the sign‑extension fix and applies to the generic Linux kernel, as no vendor‑specific version list is provided.
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Attackers would need to load or manipulate the scd30 driver, which typically requires kernel‑level privileges or control over the sensor firmware. Based on the description, it is inferred that the attack vector is limited to privileged kernel or firmware modification; no remote exploitation path is documented. The overall risk remains moderate, primarily due to potential disruption of sensor‑dependent processes rather than traditional security breaches.
OpenCVE Enrichment
Debian DLA