Impact
The vulnerability lies in the Linux kernel's DRM Panthor driver, where the firmware control interface offsets are calculated using 32‑bit arithmetic. Because the offsets are derived from firmware‑provided strides, the arithmetic can overflow before the bounds checks are performed, and the host wrapper size used does not match the size of the firmware control interface being mapped. This flaw can allow an attacker to supply crafted firmware that causes the device to access memory outside the intended bounds, potentially leading to data corruption or escalation of privileges.
Affected Systems
Affected systems are all Linux kernels that include the Panthor DRM driver, listed by the CNA as Linux:Linux. No specific version range is provided, so any kernel that compiles the Panthor driver without the applied patch is vulnerable. Firmware images or modules that use the Panthor control interface are required for exploitation.
Risk and Exploitability
The CVSS score of 7.8 classifies this flaw as high severity, but the EPSS score of < 1 % indicates that it is currently very unlikely to be actively exploited. The issue is not listed in the CISA KEV catalog. The most likely attack vector is a local attacker who can supply or influence firmware to the Panthor driver; remote exploitation would require additional foothold or privileged access to load malicious code.
OpenCVE Enrichment
Debian DLA
Debian DSA