Impact
In the Chrome OS USB Power Delivery charger driver, a flaw allows the embedded controller to report an inflated number of charger ports. The driver trusts this high count as a loop bound for an 8-slot array and writes past the array’s limits, corrupting kernel memory. This out-of-bounds write can lead to memory corruption, potential privilege escalation, or system instability.
Affected Systems
Linux kernel builds that include the cros_usbpd-charger driver, notably Chrome report charger port counts. The vulnerability applies to any kernel version that has not yet applied the fix referenced in the commit logs, as specific version ranges are not listed in the advisory.
Risk and Exploitability
The flaw does not provide a remote attack vector; an adversary would need access to the device’s EC or the ability to influence the EC’s reported values, typically requiring physical or firmware compromise. No public exploit has been 0.00168 indicates a very low exploitation probability, and the issue is not listed in the KEV catalog. The severity depends on the kernel’s privilege level, but kernel memory corruption poses a high impact if successfully exploited. Until a patch is applied, the risk could be considered moderate with potential for serious compromise if the EC can be manipulated.
OpenCVE Enrichment