Impact
The vulnerability is an integer overflow in the tda18250 media driver module of the Linux kernel. When the variable "exp" equals zero, the expression 1 << (exp - 1) evaluates to an undefined shift, which can corrupt kernel memory or otherwise lead to undefined behavior. An attacker who can influence the "exp" value may exploit this flaw, potentially causing a kernel crash or other undefined behavior. The exact impact is not explicitly stated in the advisory, but the nature of the overflow suggests serious integrity and availability risks at the kernel level.
Affected Systems
The flaw exists in the generic Linux kernel, affecting all releases that include the tda18250 media driver prior to the fix committed in the kernel source. Version ranges are not listed, so any kernel build that contains the vulnerable tda18250 code without the patch is susceptible.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a very low exploitation likelihood at the time of analysis. The primary attack vector is inferred to be local access to the tda18250 driver, typically from a user or process with permission to interact with the device. A remote exploitation scenario is not suggested by the supplied data.
OpenCVE Enrichment
Debian DLA
Debian DSA