Impact
The flaw occurs in the PCI/legacy_io sysfs interface of the Linux kernel when a user writes one‑ or two‑byte values. The kernel unconditionally loads four bytes from the user‑supplied buffer, causing an out‑of‑bounds read of up to two bytes. This read leaks kernel memory contents, representing a potential information‑disclosure vulnerability per CWE‑125. The bug does not provide a direct code‑execution path, but it could be leveraged by a root user to obtain sensitive data from the kernel space.
Affected Systems
The affected code is part of the Linux kernel on architectures that implement legacy PCI I/O support, namely Alpha and PowerPC. The legacy_io sysfs file exists only on those architectures and is writable only by root. Users of older kernel releases that contain the buggy pci_write_legacy_io implementation may be impacted, while newer kernels have integrated the endian‑aware load fix. The issue does not affect other processor families or the Alpha platform’s software because its implementation remains unchanged.
Risk and Exploitability
The CVSS score of 4.7 classifies this as a medium‑severity problem. The EPSS score is below 1 %, and the vulnerability is not listed in CISA KEV, indicating that there is no currently known widespread exploitation. An attacker would need elevated privileges to trigger the out‑of‑bounds read, so typical unprivileged users face a low risk. However, on systems where root access is compromised or where legacy PCI I/O operations are required, the leakage of kernel memory could be significant.
OpenCVE Enrichment