Impact
The vulnerability is a time‑of‑check to time‑of‑use race in the Linux kernel’s SCSI BSG interface that is used through the io_uring API. During a passthrough operation the kernel reads a BSG command structure from a shared memory submission queue element, checks its fields, and then copies user data into a kernel buffer without re‑verifying the size after the check. An attacker can modify the request_len field between the check and the copy, allowing the length to exceed the allocated command buffer and overflow the kernel’s memory. The overflow can corrupt kernel memory and potentially allow the attacker to execute arbitrary code or gain elevated privileges. The flaw therefore enables remote code execution if a local user can send specially crafted commands through io_uring.
Affected Systems
Any Linux kernel that exposes the SCSI BSG interface via io_uring without the reported fix is affected. This includes all distribution kernels that have not applied the commit or any later backport of the patch. If a system’s user land environment can interact with the BSG interface through io_uring, the kernel may be vulnerable, regardless of the distribution or specific kernel release. Patching the kernel to include the safer implementation resolves the issue.
Risk and Exploitability
The CVSS score of 7.8 places the vulnerability in the high severity range. An EPSS score of less than 1% suggests that it is not widely exploited at present, and the vulnerability is not listed in CISA’s KEV catalog. However, the local user can trigger the flaw by sending a crafted BSG command through io_uring and then altering the request length after the initial check but before the data copy. Although no public exploit exists yet, the potential for remote code execution from a local attacker warrants prompt remediation.
OpenCVE Enrichment