Impact
In the Linux kernel, the amlogic gxbb clock driver contains an out‑of‑bounds read (CWE‑119) caused by a hard‑coded parent count that does not match the actual number of clock parents. The bug was exposed by KASAN during __clk_register, revealing kernel memory contents. Although the vulnerability does not immediately allow remote code execution, the read could leak sensitive kernel information and provide a foothold for subsequent kernel exploits, raising its impact to high severity.
Affected Systems
The flaw is present in Linux kernel sources that contain the gxbb amlogic driver before the commit that fixes the parent count. Devices using Amlogic GXBB hardware—such as the WeTek Hub running 7.0.0‑rc5—are affected. Any kernel version that has not yet applied the upstream patch 7915d7d5407c is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.0 classifies the issue as high severity. The EPSS value of less than 1% indicates a low probability of current exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is most likely local: an attacker with privileged or hardware access to the affected device is needed to trigger the clock driver and read kernel memory. While the risk is significant for systems that run vulnerable kernels, realistic exploitation would require physical or firmware-level compromise rather than remote compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA