Impact
The qnap_mcu driver in the Linux kernel allocates a small on‑stack buffer for replies from the QNAP MCU. On command timeout the driver returns while the buffer is still pointed to, and a later or unsolicited reply can write into that now‑freed stack frame. This race allows an attacker who can inject a delayed response to corrupt the stack, potentially causing a crash or enabling arbitrary code execution. The weakness is a classic example of uncontrolled write to a stale buffer, corresponding to CWE-562.
Affected Systems
The affected product is the Linux kernel’s qnap_mcu driver, used in QNAP devices that expose the MCU interface over a serial device. All kernel versions prior to the patch that moved the receive buffer into the driver’s allocated structure are vulnerable. The driver appears in all Linux kernel releases, so any distribution shipping these kernels with the driver enabled may be impacted until the patch is applied.
Risk and Exploitability
The CVSS base score is 7.8, indicating a high severity. The EPSS score is less than 1%, suggesting a very low likelihood of exploitation. Because the vulnerability is not listed in the CISA KEV catalog, the vulnerability is unlikely to be currently exploited in the wild. The risk remains that an attacker with control over the serial interface to the QNAP MCU could trigger the race condition to corrupt the stack, potentially leading to a crash or arbitrary code execution if the system is vulnerable.
OpenCVE Enrichment