Impact
The Linux kernel contains an out‑of‑bounds read that occurs when reading the minimum alarm voltage in the ltc4282 driver. This flaw can allow a local attacker to read memory locations beyond the intended buffer, potentially revealing sensitive kernel data. It is tied to an improper bounds check during array access and may lead to information disclosure or kernel corruption.
Affected Systems
All Linux kernel releases that have not yet integrated the patch for the ltc4282 driver are affected. Distributions using the stock kernel prior to the commit that adds the missing return statement are vulnerable.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no public exploitation evidence at this time. An attacker would need local kernel access or the ability to interact with the ltc4282 driver to trigger the out‑of‑bounds read. Because the flaw is a read‑time error, exploitation is likely confined to local privileged users unless elevated privileges can be obtained.
OpenCVE Enrichment