Impact
In the Linux kernel, the cros_usbpd charger driver incorrectly uses the raw port count supplied by the embedded controller to iterate over charger ports. If an attacker controls the embedded controller, they can return an inflated port count of up to bounds of its allocated memory. This out‑of‑bounds write results in kernel memory corruption (CWE‑787) and could lead to a system crash or compromise of memory integrity.
Affected Systems
Any Linux system that runs kernel versions containing the vulnerable cros_usbpd driver is affected. The products listed by the CNA are generic Linux kernel releases; the vulnerability was fixed by limiting the port count to EC_USB_PD_MAX_PORTS. Specific kernel versions affected are not disclosed in the information provided.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.4, indicating a high impact. The EPSS score is below 1%, suggesting exploitation is currently unlikely in the wild. It is not listed in the CISA KEV catalog. The likely exploit path involves a malicious or compromised embedded controller that returns a false port count. The out‑of‑bounds write in kernel space can corrupt memory and potentially allow low‑level persistence or denial of service.
OpenCVE Enrichment
Debian DSA