Impact
An improper bounds check in the UBIFS superblock signature verification logic allows a crafted signed UBIFS image to cause the kernel to read beyond the allocated buffer when parsing the signature length. The flaw does not provide remote code execution; instead it can leak kernel memory contents or trigger a kernel panic due to an out‑of‑bounds read. It exists before the fix that corrects the bounds calculation, and it affects any UBIFS‑enabled Linux kernel where the signature field is present and verified.
Affected Systems
Linux kernels that employ the UBIFS file system and run a kernel version prior to the included commit are vulnerable. The flaw is present in all Linux kernel releases that expose the ubifs_sb_verify_signature routine without the subsequent patch, regardless of distribution or vendor. The affected products, as identified by the CNA, are the Linux kernel as a whole.
Risk and Exploitability
The CVSS score of 7.7 indicates serious impact, while the EPSS score of < 1% suggests very low probability of exploitation. It is not currently listed in the CISA KEV catalog. Exploitation requires the ability to supply a malicious UBIFS image to the or via remote control of a storage medium. No direct remote code execution path exists; the attacker could achieve information disclosure or denial of service if the malformed image is mounted.
OpenCVE Enrichment
Debian DSA