Impact
FPGA firmware, used in the altera_cvp module, performs an out‑of‑bounds read when it writes the last partial word of a firmware image. The code dereferences a 32‑bit pointer even when only one to three bytes are left in the input buffer. If the remaining bytes align with a page or scatter list boundary, the read can slip past the valid image data and trigger a kernel fault. Based on the description, it is inferred that this fault will trigger a kernel panic leading to a denial of service on the affected system.
Affected Systems
All Linux kernel builds that ship the default altera_cvp firmware module are affected. The affected devices include standard Linux distributions as well as custom builds that compile the kernel with the legacy altera_cvp driver. The patch has been merged into mainline; therefore, any kernel version that includes or later than the commit 4dc1051939e499c838229af035464a5fc7671198 is considered compliant. Based on the presence of the merge commit URL, it is inferred that the fix has reached the mainline kernel.
Risk and Exploitability
The CVSS score of 4.4 indicates a low severity, while the EPSS score is reported as less than 1%, signaling a very low probability of exploitation in the wild. The KEV catalog does not list this vulnerability. An attacker would need the ability to load a crafted or malformed firmware image into the FPGA, which requires write access to the device file or the firmware update interface. Based on the description, it is inferred that this fault will trigger a kernel panic leading to a denial of service on the affected system.
OpenCVE Enrichment
Debian DSA