Impact
The vulnerability exists in the Linux kernel’s media CEC subsystem, within the extron‑da‑hd‑4k‑plus driver. Malformed CEC messages can overflow the msg.msg[] buffer, corrupting kernel memory and potentially allowing an attacker to execute arbitrary code or crash the system.
Affected Systems
The affected product is the Linux kernel. Any distribution or custom kernel build that includes the media CEC subsystem and the extron‑da‑hd‑4k‑plus driver before the patch is vulnerable. No precise version range is given; the flaw exists in the kernel revision containing the unpatched media:c EC code.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity and potentially remote exploitable. EPSS is below 1%, suggesting a low immediate exploitation probability, and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote via malformed CEC messages sent by an attacker, a deduction made from the description; explicit confirmation is not provided in the advisory.
OpenCVE Enrichment
Debian DLA
Debian DSA