Impact
The vulnerability occurs in the Linux kernel on s390 systems when processing CCA AES cipher key requests. A function derives the copy length for the CPRB parameter block directly from a token length field. If the token length exceeds the actual available space, the request is not rejected early, leading to a buffer overrun. This overflow can corrupt memory and potentially crash the system. Based on the description, it is inferred that an attacker would need local or elevated privileges to contribute an oversized token, which could allow arbitrary code execution or denial of service.
Affected Systems
All Linux kernel builds that include the s390/zcrypt module are potentially affected. No specific kernel version is listed, so the risk applies to any unresolved s390 kernel.
Risk and Exploitability
The CVSS score is 7.8 and the EPSS value is unavailable, so the exact exploitation probability cannot be quantified. However, because the flaw leads to uncontrolled memory writes, it is considered a high severity issue. The vulnerability does not appear in the CISA KEV catalog, and no publicly disclosed exploits are known. Based on the description, it is inferred that the attack vector is local or requires elevated privileges, and an attacker could potentially exploit the flaw to gain arbitrary code execution or cause a denial of service.
OpenCVE Enrichment
Debian DSA