Impact
The Linux kernel s390/pkey driver contains a bounds-checking flaw in the PKEY_VERIFYPROTK ioctl. The driver accepts a user-space buffer length request structure without verifying that the requested length does not exceed the allocated buffer. Based on the description, it is inferred that an attacker could supply an oversized length, causing a kernel memory corruption that could lead to arbitrary code execution with kernel privileges. This weakness is identified as a bounds check failure (CWE-805).
Affected Systems
Affected systems include all Linux kernel implementations that incorporate the s390/pkey driver. The flaw applies to every s390‑based Linux kernel version prior to the commit that introduced the explicit length check, but the CNA does not list specific affected releases. Users running enterprise distributions on s390 hardware should verify whether their kernel contains the relevant fix.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, and the EPSS score of <1% suggests exploit likelihood is low but not negligible. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local access to invoke the PKEY_VERIFYPROTK ioctl, indicating a local privilege escalation vector. Though a publicly available exploit is not documented, the risk remains primarily theoretical until an exploit emerges.
OpenCVE Enrichment
Debian DLA
Debian DSA