Impact
In the Linux kernel, the ISST driver functions isst_if_get_perf_level_mask and isst_if_get_base_freq_mask use a user‑supplied level value directly as an index into a per‑level table without performing bounds checking. This leads to an out‑of‑bounds read from the perf_levels array, a classic CWE‑125 condition. The kernel patch adds the necessary bounds checks and rejects disabled SST‑PP levels, preventing the problematic read.
Affected Systems
The vulnerability affects Linux kernel builds that include the ISST driver and have the SST‑PP feature enabled. Because the kernel source does not specify a limited version range, any unpatched Linux installation that loads the ISST driver or exposes its control interface to user space may be vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The. Based on the description, it is inferred that the out‑of‑bounds read could allow a local attacker to read kernel memory beyond the intended bounds if a malformed ioctl request is sent. The attack vector is therefore local and requires the ability to send crafted ioctl calls to the ISST device.
OpenCVE Enrichment
Debian DSA