Impact
The flaw is in the HID subsystem that handles Corsair devices in the Linux kernel. The driver does not check the size of status and firmware events before reading them, which allows an attacker to send malformed events that trigger an out‑of‑bounds read. effectively denying local services. The weakness as CWE-125.
Affected Systems
The vulnerability affects the core Linux kernel and therefore all distributions built on it that have not incorporated the patch commits 0329354abba3, 08d8814521, or 79465a3005. No specific kernel release numbers are listed, so any kernel without those changes is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity, while the EPSS score of less than 1% shows a very low likelihood of active exploitation. The flaw is not listed in the CISA KEV catalog. An attacker would need local physical or logical access to a Corsair HID device to inject malformed events and trigger the out‑of‑bounds read, denial of service. The attack vector is therefore inferred to be local device interaction.
OpenCVE Enrichment