Impact
The Linux kernel platform/x86 panasonic‑laptop driver performs a sentinel write beyond the bounds of the pcc->sinf array, an out‑of‑bounds write identified as CWE‑787. This silent 4‑byte heap overflow corrupts kernel memory during ACPI table parsing when a malicious or malformed SINF package is processed.
Affected Systems
All Linux kernel releases that include the platform/x86 panasonic‑laptop driver before the commit that removes the off‑by‑one sentinel write are affected. The vulnerability is triggered when the kernel uses the num_sifr++ workaround to accommodate DSDT off‑by‑one bugs, which makes the array bounds check vulnerable. Systems running on Panasonic laptops or any hosts that load this driver and have not applied the patch are at risk.
Risk and Exploitability
The CVSS base score of 7.8 classifies this as high severity. The EPSS score of <1% and absence from CISA KEV suggest a low exploitation probability at present. Based on the description, it is inferred that exploitation requires local access to supply a malicious ACPI or DSDT table that the panasonic‑laptop driver will parse, typically demanding firmware control or physical manipulation. A successful trigger would cause silent 4‑byte kernel heap corruption with undefined consequences.
OpenCVE Enrichment