Impact
The Linux kernel driver for Kvaser USB devices mishandles variable‑length commands. A non‑zero command shorter than the expected header length can be dispatched, and the driver copies this into a fixed caller‑owned structure without proper bounds checking. This oversight creates a potential buffer overflow at kernel level, which could destabilize the system or allow execution of arbitrary code with kernel privileges.
Affected Systems
All Linux kernel versions that include the kvaser_usb driver until the fix is applied. The vulnerability is inherent in the driver implementation and is not limited to a specific kernel release according to the available data.
Risk and Exploitability
The description indicates a flaw in a kernel driver; exploitation requires the ability to send crafted USB commands to the device, suggesting a local or device‑attached attack vector. The EPSS score is < 1%, the CVSS score is 5.5, and the vulnerability is not listed in KEV; these metrics indicate a moderate risk level, with the severity moderate and exploit likelihood low.
OpenCVE Enrichment
Debian DSA