Impact
The Linux kernel’s DRM subsystem in the sysfb driver contains an integer overflow in the calculation of framebuffer size. The calculation fb_size = linebytes * height uses int operands; if both linebytes and height are large, multiplication can exceed INT_MAX, triggering undefined behavior. This overflow allows an attacker to potentially influence how kernel memory is allocated or accessed for framebuffers, leading to kernel memory corruption and possible privilege escalation.
Affected Systems
The issue exists in the Linux kernel’s DRM subsystem, specifically the sysfb driver’s ofdrm configuration. All Linux distributions that ship a kernel version prior to the stable commit adding check_mul_overflow() are affected. The change is part of the generic Linux kernel; no specific vendor scope beyond the Linux kernel itself.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, and the EPSS score of less than 1% shows a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation documented yet. Based on the description, it is inferred that an attacker would need to trigger the framebuffer size calculation with large dimensions—i.e., influence the linebytes and height values—through a local or privileged interface such as a graphics driver or ioctl. This suggests the attack vector is likely local or requires elevated privileges, and from the overflow it may lead to arbitrary kernel memory writes and privilege escalation.
OpenCVE Enrichment