Impact
eCryptfs_parse_packet_set() receives a pointer into the file header, but it calculates the remaining packet buffer size from PAGE_SIZE - 8. For version 1 headers the packet set starts later in the header, so this can overstate the available buffer. This overestimation can cause the function to read beyond the intended data boundaries, potentially leading to kernel memory corruption that may result in a crash or, if exploited further, compromise the integrity of the kernel. The flaw is a classic buffer overflow vulnerability (CWE-131).
Affected Systems
All Linux kernel builds that include the eCryptfs subsystem and lack the upstream commit that fixes ecryptfs_parse_packet_set() remain affected. Kernel versions prior to the patch that applies the corrected buffer size calculation are vulnerable release contains the commit that modifies the packet parsing logic.
Risk and Exploitability
The likely attack vector is local or requires privileged access, as the vulnerability requires the victim to process a crafted eCryptfs packet set during file parsing when an eCryptfs encrypted file is accessed or mounted. The CVSS score of 7.1 reflects a medium‑to‑high severity, while the EPSS score of less than 1% indicates a low exploitation probability at present. Because the flaw requires the victim to process a crafted encrypted file, remote exploitation would need a separate vector to supply the malformed data. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DSA