Impact
The flaw exists in the UDF 1.50 virtual partition handling in the Linux kernel. During processing of a UDF filesystem, the routine that maps virtual block addresses to physical blocks accepts an index that is equal to the number of entries in the Virtual Address Table. This off‑by‑one error lets a crafted UDF image read one element beyond the table’s bounds, causing a KASAN slab‑out‑of‑bounds error and potentially a kernel panic. The bug corresponds to CWE‑1285 – Off‑by‑One Error – and could leak memory contents and force the system to reboot, but the current public evidence indicates a denial‑of‑service outcome rather than remote code execution.
Affected Systems
Any distribution that incorporates a Linux kernel containing UDF 1.50 virtual partition support before the fix, identified by the kernel commit 0e35b9b6. This includes a broad set of consumer and enterprise Linux releases whose kernels have not yet been updated with the boundary‑check change.
Risk and Exploitability
The fixed CVSS score is 4.0, and the EPSS score is less than 1%, showing a low likelihood of exploitation. It is not listed in CISA KEV. The likely attack vector, based on the description, is local: an attacker must supply a malicious UDF image that the kernel processes, such as via removable media or an untrusted filesystem image. The vulnerability can lead to a kernel panic and system denial of service, with no publicly documented code‑execution path.
OpenCVE Enrichment
Debian DSA