Impact
In the Linux kernel the NSM (Network Sensor Module) driver fails to bound the response length reported by a backend device. The length is stored in msg->resp.len without checking against the actual buffer size. When parse_resp_raw copies the data to user space, it reads past the end of the kernel buffer, disclosing adjacent kernel heap memory. This flaw allows an attacker with control over a buggy or malicious NSM backend to read arbitrary kernel memory, providing a potential information‑disclosure oracle that could be leveraged for further privileged exploits. It is a classic out‑of‑bounds read weakness (CWE‑125).
Affected Systems
Any Linux system running a kernel that contains the unpatched NSM driver—specifically kernels before commit 29e634a18957acda11383a15ab98a91c4ae9e294. This includes stock kernels and distributions that have not applied the patch, as well as custom kernel builds that incorporate the same logic. The module may remain vulnerable even if not actively loaded, because the flaw exists in the driver code present in the kernel image.
Risk and Exploitability
The vulnerability has a CVSS base score of 7.7, categorizing it as high severity. The EPSS score is below 1 %, indicating that real‑world exploitation is unlikely at present. It is not listed in CISA’s KEV catalog. Exploitation requires the ability to influence a NSM backend device to supply a malformed response length, making the attack vector device‑specific and not a typical remote exploit. The low EPSS suggests that, unless the attacker has physical or privileged access to the device, the risk remains modest, yet the read disclosure can serve as an attack facilitator in higher‑privilege scenarios.
OpenCVE Enrichment
Debian DSA