Impact
An overflow in the ACPI pfr_update subsystem occurs when the kernel copies‑supplied buffer into stack memory without validating the buffer length. If the firmware returns a longer buffer, the memcpy writes beyond the array boundary in kernel memory corruption that can crash the system or allow further exploitation. The flaw is a classic stack buffer overflow (CWE-120).
Affected Systems
The vulnerability affects Linux kernel implementations that have not‑validation commit. All dist query as indicated by the product name Linux and the kernel CPE entry. No specific product version range is supplied in the data, so the only indicator is that the fix has been applied in newer kernels.
Risk and Exploitability
The CVSS score of 7.8 classifies the flaw as high severity. The EPSS score of <1% suggests a very low probability of exploitation, and it does not appear in the CISA KEV catalog. The flaw requires that an attacker supply an oversized ACPI buffer via a _DSM entry, which typically means having control over the system firmware or access to physical hardware to inject a custom ACPI table. Based on the description, this is inferred as the likely attack vector.
OpenCVE Enrichment
Debian DSA