Impact
The Linux kernel's vfio_ccw driver does not enforce bounds checks on indices used for read/write regions. This oversight permits an attacker to supply out‑of‑bounds indices, enabling arbitrary kernel memory reads or writes. The resulting kernel memory corruption can be leveraged to escape privilege limits and compromise the system.
Affected Systems
All Linux kernel builds running on IBM s390 architecture that include the vfio_ccw driver prior to the bug‑fix commit. The vulnerability appears in any kernel version lacking the proper bounds‑checking implementation, irrespective of distribution or patch level.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity. The EPSS score of 0.00129% indicates a very low but non‑zero likelihood of exploitation, and it is not listed in the CISA KEV catalog, so the current exploitation probability remains low. The likely attack vector is local or potentially remote through any user‑space interface that invokes vfio_ccw; specific exploitation steps are not documented in the provided data.
OpenCVE Enrichment
Debian DLA