Impact
The DS28E17 1‑Wire to I²C bridge driver allows a device to supply a length byte that represents the number of data bytes to read. The driver copies that many bytes into a 34‑byte buffer, causing a read past the end of the buffer up to about 222 bytes. This out‑of‑bounds read can expose kernel memory contents, potentially leaking sensitive information. The flaw is a classic unchecked buffer read represented by CWE-125.
Affected Systems
All Linux kernel installations that load the DS28E17 driver, with no specific kernel version range listed, as the vulnerability exists in any kernel build that includes the unpatched driver code referenced in the commit logs.
Risk and Exploitability
The CVSS v3 base score of the flaw is 7.8, indicating a high severity vulnerability. The EPSS score of less than 1% indicates a very low probability that this vulnerability will be seen in real-world exploitation at present. It is not listed in CISA’s KEV catalog. The primary vector for exploitation is physical or local access to the I²C bus, where a malicious or compromised device could issue an I²C_M_RECV_LEN transaction with an oversized length byte. Since the vulnerable code resides in kernel space and the flaw involves an unchecked buffer read, a successful exploitation could lead to information disclosure of kernel memory contents, potentially allowing privilege escalation or further attacks. The vulnerability is not remotely exploitable over a network.
OpenCVE Enrichment
Debian DSA