Impact
In the Linux kernel MTD RAW NAND driver, the function used to parse ONFI extended parameter pages does not verify that each declared section fits within the allocated buffer. This omission allows a provider‑supplied NAND device to supply a malformed ONFI page that causes the driver to read beyond the buffer bounds, potentially exposing kernel memory or leading to a driver crash. The flaw is an unwarranted buffer over‑read stemming from insufficient input validation.
Affected Systems
The vulnerability concerns the raw NAND driver in the Linux kernel. Any installation using the kernel's MTD rawnand module – which parses ONFI extended parameter pages – is potentially impacted. The flaw applies to all kernel releases that include this code path, and no specific version ranges are supplied. Systems running the raw NAND driver without a patched kernel may be vulnerable.
Risk and Exploitability
The vulnerability is considered low probability of exploitation, with an EPSS score of <1% and no listing in the CISA KEV catalog, indicating limited public interest. A local attacker controlling the NAND device or its firmware can supply a crafted ONFI page; a remote attack path is not described. The lack of an immediate remote exploitation surface reduces overall risk, though kernel memory disclosure remains a concern for affected hosts.
OpenCVE Enrichment
Debian DLA
Debian DSA