Impact
The vulnerability occurs in the Linux kernel’s dm raid1 module where a buffer overflow can happen while constructing a string representation of a 64‑bit value. The flaw arises because the code reserves only space for the decimal digits but does not allocate an additional byte for the terminating NUL, causing a possible overflow in sprintf. This overflow could overwrite adjacent memory, potentially corrupting kernel data structures and leading to crashes or arbitrary code execution if the attacker can influence the string.
Affected Systems
Affected systems are Linux kernels that include the dm raid1 device manager before the fix is integrated. This includes all current and older releases that still ship the vulnerable code. The CNA vendor list notes Linux:Linux, and the CPE indicates linux_kernel. No specific versions were enumerated, so any kernel lacking the patch is vulnerable.
Risk and Exploitability
The CVSS score of 4.7 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, implying no widespread exploitation has been documented. Based on the description, the attack vector is local: an attacker would need to provide a malicious dm raid1 configuration or load a module with crafted parameters, which typically requires root or kernel privilege on the target system.
OpenCVE Enrichment
Debian DSA