Impact
An out‑of‑bounds read occurs in the Linux kernel’s Qualcomm battery manager driver when firmware supplies a string that is not properly null‑terminated. The driver copies the string into three adjacent buffers – model_number, serial_number and oem_info – each sized BATTMGR_STRING_LEN. If a firmware string consumes the entire buffer, the subsequent string prints with printf "%s" continue into the following memory, exposing data beyond the intended fields. This defect corresponds to CWE‑125 does not provide direct code execution or denial of service.
Affected Systems
The flaw resides in the Linux kernel’s qcom_battmgr driver; any kernel package that contains this module before the patch is affected. Systems operating Qualcomm hardware such as the SC8280XP that depend on the battery manager firmware are at risk. Exact kernel release versions are not documented, but any build prior to the commit that introduced strscpy handling will be vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 7.7 indicates a medium‑to‑high impact. Attackers would need to supply malformed firmware or gain the ability to alter firmware strings, which typically requires privileged access; the likely attack vector is through manipulation of the battery manager firmware, inferred from the need to control firmware strings during device operation. The EPSS score of < 1% indicates a very low exploitation probability. No remote code execution or denial‑of‑service effect is described, so the primary risk is potential information disclosure.
OpenCVE Enrichment
Debian DSA