Impact
The Linux kernel Thunderbolt driver contains an unchecked array index: the six‑bit field dual_link_port_nr read from a device’s DROM may exceed the allocated sw->ports[] array. This allows a malicious or malformed Thunderbolt device to cause an out‑of‑bounds pointer write that is later dereferenced, potentially corrupting kernel memory and giving the attacker local privilege escalation or a system crash.
Affected Systems
Any Linux kernel build that includes the Thunderbolt driver and has not yet been updated with the patch is vulnerable. The exact kernel versions are not listed, but all kernels running the unpatched driver are affected.
Risk and Exploitability
Because the flaw permits out‑of‑bounds memory writes in kernel space, exploitation could lead to privilege escalation or a system crash. The likely attack vector is physical connection of a malicious Thunderbolt device, as the vulnerability is triggered by device‑supplied DROM entries. Based on the description, the attacker would need physical access to a device that can provide a malicious DROM payload. The CVSS score is 5.5 and the EPSS indicates a very low exploitation probability (<1%). The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation, but the risk remains if a compromised device is attached.
OpenCVE Enrichment
Debian DLA
Debian DSA