Impact
An out‑of‑bounds write occurs in the Linux kernel crypto IAAs decompression routine when a hardware error forces a fallback to software decompression. While SWIOTLB is active, the destination buffer remains mapped for DMA_FROM_DEVICE and the software path writes over stale data, corrupting the output. This flaw is a classic memory corruption bug (CWE‑787) that can lead to data integrity problems and potentially disrupt cryptographic operations.
Affected Systems
All Linux kernel builds that include the crypto IAAs decompression feature and have not applied the upstream change are affected. The issue is present across all vendor distributions that ship the kernel without the patch; no specific version numbers are listed in the CNA data.
Risk and Exploitability
The CVSS score of 9.1 signals a high‑severity flaw, while the EPSS score of less than 1 % reflects a very low but non‑zero likelihood of exploitation. The vulnerability is not flagged in CISA’s KEV catalog. Real‑world exploitation would require an attacker to induce a hardware error that triggers the decompress retry with SWIOTLB enabled—an action that is non‑trivial and typically demands privileged or specialized hardware. Consequently, while the potential impact is severe, the probability of exploitation in the wild remains low.
OpenCVE Enrichment
Debian DSA