Impact
During fuzz testing, the Linux kernel was found to leave two padding bytes uninitialized in the scatter‑list tables created by scsi_alloc_sgtables(). Those bytes are carried through the DMA mapping process and can be exposed in SCSI IO operations, representing a use of uninitialized memory. The description notes that the uninitialized bytes lead to a problem, but it does not explicitly identify the consequences beyond the presence of leftover memory.
Affected Systems
The vulnerability affects all Linux kernel versions that contain the legacy SCSI core implementation and have not incorporated the patch identified by commit 6261477. The affected component is the scsi_alloc_sgtables routine in the core SCSI subsystem; no specific version range is provided, so any kernel prior to the commit is potentially impacted.
Risk and Exploitability
The CVSS base score of 6.3 indicates moderate severity. EPSS is reported as <1%, signifying a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation would likely require local access to perform a SCSI ioctl that triggers the uninitialized padding, so the risk remains moderate pending remediation.
OpenCVE Enrichment
Debian DSA