Impact
In the libnvdimm subsystem of the in the __nd_label_validate() function. The function multiplies the on‑media namespace index (nslot), a 32‑bit value read from the DIMM label or supplied via ND_CMD_SET_CONFIG_DATA, by the runtime label size using 32‑bit arithmetic. This product can wrap around modulo 2^{32} before the bound check is performed. A crafted nslot value can therefore pass the bounds test and become the loop counter in nd_label_data_init(). The memset used there walks past the end of the configuration buffer, resulting in an out‑of‑bounds write and corruption of kernel memory.
Affected Systems
All Linux kernel builds that include the libnvdimm subsystem before the 64‑bit bound check introduced in commit 564e871aa66f are potentially affected. Kernel configurations that enable NVDIMM handling are at risk; any build without the commit may be vulnerable until the patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a very low exploitation probability. The vulnerability is not listed in CISA KEV. Exploitation would likely require local or privileged access to supply a crafted ND_CMD_SET_CONFIG_DATA request or to manipulate the on‑media label. Based on the description, it is inferred that an attacker can abuse the ND_CMD_SET_CONFIG_DATA interface to inject a malicious index, triggering the integer overflow and ensuing out‑of‑bounds write.
OpenCVE Enrichment
Debian DSA