Impact
An off‑by‑one error in the kernel’s TDX port I/O handlers causes the mask used for 8‑bit access to be one bit too wide, producing a 9‑bit mask instead of the intended 8 bits. This leads to incorrect data being read from or written to I/O ports, potentially corrupting kernel data. Based on the description, it is inferred that exploitation requires local kernel privilege or a user with TDX port I/O access.
Affected Systems
The issue is confined to the Linux kernel on x86 architectures where arch/x86/coco/tdx/tdx.c is compiled. Any kernel build that has not incorporated the patch is vulnerable; the CPE entry identifies the general Linux kernel product but does not specify affected version ranges.
Risk and Exploitability
Based on the description, it is inferred that exploitation requires local kernel privilege or a user with TDX port I/O access. The CVSS score of 4.7 indicates moderate severity, while the EPSS score of less than 1% reflects a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation requires local kernel access or a privileged actor capable of performing TDX port I/O, with no known remote code execution path. Thus the risk is considered low to moderate, depending on the environment.
OpenCVE Enrichment
Debian DSA