Impact
In the Linux kernel, the media driver for NXP i.MX 8 Integrated Sensory Interfaces (ISI) lacked a minimum value check for its down‑scaling factor, allowing a value of up to 16 to be written directly to hardware registers. This out‑of‑bounds write can corrupt kernel memory and cause the requesting process to become unresponsive, effectively denying service to that process.
Affected Systems
All Linux kernel builds that include the imx8‑isi media driver are affected until the fix is applied. The vulnerability applies to any kernel configuration or custom build that compiles the imx8‑isi module, as the specific kernel version is not enumerated in the advisory.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation is currently unlikely. The flaw is a local denial‑of‑service issue that requires the ability to control the ISI down‑scaling factor, such as by issuing compatible ioctl calls from a user‑space application with access to the device. Remote exploitation would require additional privileges or further vulnerabilities and is therefore considered less probable.
OpenCVE Enrichment
Debian DLA