Impact
A flaw in the Linux kernel’s net1080 USB driver allows an attacker controlling a NetChip 1080 device to send a specially crafted packet with an oversized even length, causing the driver to read beyond the end of the socket buffer before validating the packet size. This leads to an out-of-bounds read of the packet’s pad byte, potentially corrupting kernel memory and resulting in a system crash or denial of service. The vulnerability is classified as a memory corruption weakness (CWE‑125).
Affected Systems
All Linux systems that load the net1080 USB driver are potentially affected. This includes most Linux distributions that ship the kernel driver for NetChip 1080 hardware. The defect has been addressed in kernel patches that update the rx_fixup routine; any installation lacking those patches remains vulnerable.
Risk and Exploitability
The CVSS score is 8.1, indicating high severity, while the EPSS score is below 1%, implying a low but non-zero exploitation probability. The flaw is not listed in the CISA KEV catalog. Exploitation requires a malicious USB NetChip 1080 device physically connected to the target or placed in the data path; the attack vector is local and device-based. Once triggered, the out-of-bounds read can lead to a kernel panic and denial of service, but no remote code execution or privilege escalation is directly supported by the current description.
OpenCVE Enrichment
Debian DLA
Debian DSA