Impact
This vulnerability in the Linux kernel’s HID subsystem allows an attacker to overflow a heap buffer used by the intel‑thc‑hid: intel‑quickspi_FEATURE ioctl with a report larger than the driver’s maximum report length, the kernel copies the attacker‑controlled data into a buffer that is not properly sized, corrupting kernel memory. Such corruption can lead to arbitrary kernel’s control flow.
Affected Systems
All Linux kernel installations that include the intel‑thc‑hid: intel‑quickspi driver are affected. No specific kernel or device release is listed, so any kernel version containing this driver without the patch is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is not currently listed in CISA’s KEV catalog. Based on the description, it is inferred that local access may be required, as the vulnerability involves a kernel buffer overflow triggered by a HID ioctl. The overflow can corrupt kernel memory, potentially enabling privilege escalation or code execution.
OpenCVE Enrichment