Impact
In the Linux kernel IPMI IPMB stack, the write handler parses IPMI messages before validating write causes the routine to read uninitialized stack bytes, and a length smaller than the SMBus header underflows the block write length. Because the buffer and length are not checked up front, an attacker can supply crafted IPMI write commands that allow reading kernel memory contents. This improper input validation and use of uninitialized memory can lead to the disclosure of privileged data, impacting confidentiality but not integrity or availability.
Affected Systems
All Linux kernel releases that contain the IPMI IPMB stack could be affected, as the commit series referenced in the advisory introduces supplied in the advisory; therefore, any kernel prior to the inclusion of these commits remains vulnerable. Users should upgrade to a kernel that incorporates the patch commits 53637506884dbd5c91a89b1a3547d99d80f8ed2c, 5719431ca2b5fa26560bb38f6202f8b97fa3bbb0, 60939bcda6f3f104ef456fdbf3cc5733c0720fb1, or a84c6e3d188f2c6e674910929eb790634299d6d5.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity, and the EPSS score of less than 1% and absence from the CISA KEV catalog imply a low probability of public exploitation. Exploitation requires the ability to send custom IPMI write commands, which is typically restricted to privileged users or can be performed remotely through an external BMC if exposed. The likely attack vector is local or remote IPMI write operations that supply a message with an invalid length IPMI messaging can read kernel memory and potentially leak confidential data.
OpenCVE Enrichment
Debian DSA