Impact
A bounds-checking flaw in the Linux kernel’s panthor firmware loader allows an overflow when adding the metadata start and size values, which can cause an out‑of‑bounds range to pass validation. The loader also reads a ‘git_sha: ’ prefix without verifying that the metadata is long enough, and a zero size can underflow the NULL terminator index. An attacker who can supply crafted firmware metadata may exploit this to read or corrupt kernel memory, potentially leading to privilege escalation or arbitrary code execution. The vulnerability is classified as an integer overflow or wraparound and a buffer overread.
Affected Systems
This flaw exists in the Linux kernel wherever the drm/panthor firmware loading path is present. No specific kernel release versions are listed in the advisory; any kernel that contains the panthor_fw_read_build_info function is potentially affected.
Risk and Exploitability
The CVSS 7.1 score indicates high impact if exploited. EPSS is under 1%, suggesting the probability of exploitation is low at present. The vulnerability is not listed in the CISA KEV catalog, and the attack likely requires an attacker to supply malicious firmware to the DRM subsystem, implying local or privileged access. Without readily available exploit code and given the low EPSS, the overall risk remains moderate but non‑negligible.
OpenCVE Enrichment