Impact
The flaw lies in the Linux kernel's ACPI APEI GHES handler for ARM devices, where the remaining length for parsing CPER sections is incorrectly reduced by a pointer size instead of the full error header structure size. This mis‑calculation inflates the perceived number of bytes left for CPER records, allowing the parser to read past the actual CPER data and potentially read that destabilizes the kernel.
Affected Systems
All Linux kernel builds that include the ACPI APEI GHES handler for ARM and process CPER tables are potentially affected until the commit that corrects the length accounting is applied. The advisory does not specify exact kernel-version ranges, so any system running a kernel prior to the inclusion of the patch remains vulnerable.
Risk and Exploitability
The CVSS score of 8.4 classifies this flaw as high severity. The EPSS score of less than 1 % indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is delivery of a malformed CPER payload, which may be achieved through firmware updates or local access. Based on the description, it is inferred that this attack can trigger an out-of-bounds read.
OpenCVE Enrichment
Debian DSA