Impact
The vulnerability arises from the kernel driver for the s2255 media device. The probe routine reads a 4‑byte marker and a version number from the end of the firmware image. If the firmware is shorter than 8 bytes, the calculation fw_size - 8 overflows, resulting in an out‑of‑bounds read. This can expose arbitrary kernel memory contents to any process that can trigger the firmware load, compromising confidentiality.
Affected Systems
The issue exists in the Linux kernel across all versions released before the patch was applied. The CWE categorization is related to integer underflow leading to a buffer over‑read in the driver code. There is no currently known vendor‑specific version list; the fix is in the mainline kernel source.
Risk and Exploitability
The CVSS score is not provided, but the EPSS score is < 1 % and the vulnerability is not listed in CISA KEV, indicating a low current exploitation probability. The attack requires ability to trigger the s2255 firmware probe with a maliciously sized firmware file, which could be done by a local attacker or a trusted device. The severity is mild to moderate depending on the sensitivity of the exposed memory, but patching remains advisable.
OpenCVE Enrichment
Debian DLA
Debian DSA