Impact
The cros_usbpd‑charger driver in the Linux kernel incorrectly trusts the embedded controller’s reported number of charger ports. The reported value is used as a loop bound for an 8‑entry array. If a malformed EC supplies a number larger than the array size, the loop writes beyond the array, corrupting kernel memory. This out‑of‑bounds write is a classic heap overflow (CWE‑787).
Affected Systems
The flaw exists in any Linux kernel build that includes the cros_usbpd‑charger driver before the patch that bounds num_charger_ports. This driver exposes EC USB‑PD port counts. Versions of the kernel prior to the commit referenced in the git logs are vulnerable, while all kernels which incorporate the new bounds check are safe.
Risk and Exploitability
Risk originates from a heap out‑of‑bounds write that can corrupt kernel memory. The CVSS score of 8.4 indicates high severity, while the EPSS score of less than 1 % suggests a very low probability of public exploitation at present. The vulnerability is not listed in CISA's KEV catalog. The most likely scenario for exploitation, based on the description, is that an attacker or a malfunctioning embedded controller provides an invalid port count that exceeds the array size, causing the driver to write beyond its bounds. However, the exact attack vector and whether an exploit is possible outside of a compromised or physically accessed EC are not explicitly documented, so these details remain uncertain.
OpenCVE Enrichment
Debian DSA