Impact
The Linux kernel’s stm32 CEC driver appends each received byte to an array that has a fixed size of 16 elements. The driver increments the write index on every receive interrupt without verifying that it remains within the buffer bounds. When a remote peer sendsEC frame, the driver writes past the end of the array and overwrites adjacent memory. This classic buffer‑overflow flaw (CWE‑787) can corrupt kernel data structures, potentially causing a crash, loss of integrity, or, in the worst case, an indeterminate state.
Affected Systems
All Linux kernel distributions that include the stm32 CEC driver before the commit that introduces a bounds check are affected. The bug is present whenever the driver is built and enabled, which is typical on embedded devices that use an STM32 processor with CEC support. Systems that compile this module for any architecture—such as ARM or x86—carry the same risk if they expose the CEC interface.
Risk and Exploitability
The vulnerability scores 8.8 on the CVSS scale and has an EPSS of <1 %. It is not listed in the CISA KEV catalog, indicating no widespread exploitation has been observed to date. The flaw is reachable during normal operation; an attacker only needs the ability to inject CEC packets at the target device. Because the vulnerability is triggered in an interrupt context without privilege checks, any remote peer capable of sending CEC frames can invoke the overflow, potentially leading to denial of service or corrupted system state.
OpenCVE Enrichment
Debian DSA