Impact
The vulnerability is an out-of-bounds read in the Linux kernel’s CXL (Compute Express Link) subsystem. During fwctl command handling the kernel allocates a buffer sized to a user-supplied length but later ignores that length when accessing the buffer, allowing a crafted command to cause a read past the end of the allocated area. This out-of-bounds read can trigger a kernel OOPS and crash, resulting in denial of service.
Affected Systems
All Linux kernel releases that include the cxl/features module before the security fix. Distribution or vendor is not specified; any installation that ships a kernel with the cxl subsystem and has not applied the patch is vulnerable. The problem appears in paths that handle fwctl commands for CXL features, so any system exposing the CXL device interface is at risk. Version information is not provided.
Risk and Exploitability
The CVSS score of 7.1 denotes high severity. The EPSS score is less than 1%, indicating that exploitation in the wild is unlikely, and the vulnerability is not listed in the CISA KEV catalog, so no known active exploits have been reported. Based on the description, the likely attack vector is local access to the CXL interface; an attacker or a compromised privileged process that can issue a crafted fwctl command can trigger the out-of-bounds read, causing the kernel to oops and crash, leading to denial of service. No privilege escalation or remote code execution is described.
OpenCVE Enrichment