Impact
The vulnerability is a bounds‑checking flaw in the AFS v2 image parser of the Linux kernel. The parser reads footer[8] from flash memory to locate an image information block and uses the region_count value from the image to index a fixed‑size local array. Because neither the footer offset nor the region_count is validated against the size of the erase block or the array length, an attacker can supply crafted flash data that causes the parser to read or write past the bounds of the array. This memory corruption in kernel space can result in arbitrary code execution or a kernel crash, effectively allowing privilege escalation.
Affected Systems
All Linux kernel builds that include the vulnerable AFS v2 parser before the fix are affected. The product is the Linux kernel distributed by the Linux community. No specific kernel version numbers are listed, therefore any kernel that has not yet incorporated the commit series referenced in the advisory could be at risk.
Risk and Exploitability
The CVSS score of 8 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that, at present, exploitation is unlikely, and the flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires an attacker to have local access to flash storage or the capability to write a crafted firmware image, making the threat most relevant to embedded devices or systems with exposed MTD interfaces. If an attacker succeeds in delivering a malicious flash image, the unchecked bounds could overwrite kernel memory, leading to privilege escalation or a denial‑of‑service condition.
OpenCVE Enrichment
Debian DLA
Debian DSA