Impact
cxl_rch_get_aer_info() copies an AER capability block using a loop based on sizeof(struct aer_capability_regs). The struct includes a pcie_tlp_log field that is larger than the on‑wire AER register block, so the loop reads beyond the mapped register region. The over‑read populates software‑only tail fields such as header_log.header_len, which can be leveraged by pcie_print_tlp_log() to perform a second out‑of‑bounds read. This flaw enables an attacker to read kernel memory, potentially leaking confidential data.
Affected Systems
Any Linux kernel image that includes the cxl/ras driver and has not incorporated the patch that bounds the read to the physical AER registers is vulnerable. No any distribution exposing a CXL Root Complex Host device with the unpatched driver should be examined for susceptibility.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high severity, while the EPSS <1% and absence from the CISA KEV catalog suggest a low likelihood of real‑world exploitation. The vulnerability requires local privilege or the ability to influence interactions with a CXL RCH device, limiting the attack surface. Consequently, the overall risk is considered moderate, driven primarily by the restricted attack vector and low exploitation probability.
OpenCVE Enrichment
Debian DSA