Impact
The issue arises in the megaraid_sas NVMe PRP build routine, where the code does not enforce the boundaries of the DMA pool buffer. Each NVMe page adds a PRP entry, and because the loop never checks the buffer bound, it may write beyond the allocated region. The overflow can corrupt adjacent PRP lists or other kernel control data, potentially leading to a kernel panic or allowing an attacker to alter data or gain higher privileges if they can influence the overwritten contents.
Affected Systems
Affected systems are Linux kernel images that contain the megaraid_sas driver without the fix that caps max_hw_sectors at the size of the PRP chain frame. The list of specific kernel releases is not provided, but any build that includes the megaraid_sas module and has not been patched with the commit fixing the PRP size is susceptible.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, yet the EPSS score is below 1%, and the vulnerability is not currently catalogued in CISA KEV. Exploitation requires the ability to send NVMe commands to a megaraid_sas device, so the likely attack vector is local or requires direct hardware access. Given the low exploitation probability, the risk to organizations that can reach the affected hardware is moderate but should be mitigated promptly.
OpenCVE Enrichment