Impact
The kernel’s sensorhub driver processes events from the embedded controller, each event containing an 8‑bit sensor number. The handler validates FIFO event counts and ring bounds but fails to verify the sensor number before using it as an index into the batch_state array. An attacker that can supply a sensor number equal to or larger than the declared count can trigger an out‑of‑bounds read or write on batch_state, corrupting kernel memory and potentially destabilizing the system.
Affected Systems
Linux kernel builds that include the platform/chrome sensorhub driver without the sensor-number validation patch are affected. No specific kernel releases are listed, so any unpatched kernel version that ships with this driver may be vulnerable.
Risk and Exploitability
The vulnerability is rated CVSS 8.4 (v3.1), and its EPSS score of less than 1 % indicates a low current exploitation probability. It is not in CISA KEV. The likely attack vector is exploitation of the EC interface; an adversary would need to influence the embedded controller to transmit malformed sensor numbers. If such control is achieved, the kernel memory corruption could lead to system instability or compromise, but the overall threat is modest without that capability.
OpenCVE Enrichment
Debian DSA