Impact
A Linux kernel flaw in the SCSI block layer can cause an unchecked copy of a SCSI sense buffer into a user‑supplied response buffer. The kernel copies the full sense_len, up to SCSI_SENSE_BUFFERSIZE, without respecting the supplied max_response_len. This results in a classic buffer overflow that may corrupt adjacent memory and potentially allow a privileged or local attacker to execute code, crash the system, or perform other destructive actions. The weakness is a classic Buffer Overflow (CWE‑119).
Affected Systems
The vulnerability applies to all releases of the Linux kernel; vendors Linux:Linux are affected. No specific version range is listed, so any kernel without the patch is vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS of less than 1% suggests a low probability of exploitation at the time of analysis, and the vulnerability is not yet listed in CISA KEV. The attack is most likely a local one, though a remote attacker might trigger the SCSI command path via networked SCSI subsystems. No additional exploitation conditions are disclosed in the description.
OpenCVE Enrichment