Impact
A buffer overflow occurs in the Linux kernel’s DRM i915 driver when the streams[] array bounds are validated only after a memory write has taken place. This flaw can corrupt kernel memory and, if exploited, allows an attacker to execute arbitrary code with elevated kernel privileges.
Affected Systems
The vulnerability resides in the Linux kernel’s DRM i915 driver used for Intel GPU HDCP. Any Linux machine running kernel versions prior to the patch represented by commit 9284ab3b6e776c315883ac2611283d263c9460fd is considered vulnerable. No specific version range is listed, so all earlier kernel releases should be assessed.
Risk and Exploitability
Because the vulnerability lies in kernel space, successful exploitation would grant kernel-level privileges. The CVSS score of 7.8 indicates a high severity. The EPSS score is < 1%, pointing to a very low but non‑zero likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. It is likely exploitable by a local user who can communicate with the GPU via DRM—for example, by sending malformed HDCP or DRM requests—to trigger the buffer overflow during kernel-mode GPU data handling.
OpenCVE Enrichment
Debian DSA