Impact
The Linux kernel’s UCSI displayport driver back‑ends the current camera mode (GET_CURRENT_CAM) to index a port alternate mode array that is sized to UCSI_MAX_ALTMODES. If the PPM returns a mode index larger than this size and not equal to the sentinel 0xff, the driver will read past the array bounds. This out‑of‑bounds memory access can trigger a kernel panic, resulting in a denial‑of‑service for all users on the affected machine.
Affected Systems
The vulnerability is present in all Linux kernel versions that implement the legacy UCSI displayport driver without the added bounds check. This includes any distribution kernel that contains the ucsick_displayport.c code prior to the commit that implements the verification of the current cam against UCSI_MAX_ALTMODES. Consequently, systems running older releases of the Linux kernel that expose the UCSI interface for USB‑C displayport support are susceptible.
Risk and Exploitability
The CVSS score of 7.7 classifies the issue as high severity, while the EPSS score of less than 1% indicates a low probability of real‑world exploitation. The problem is not listed in CISA’s KEV catalog. The likely attack vector requires an attacker to provide a USB‑C device capable of acting as a UCSI host and to send a crafted GET_CURRENT_CAM response. No public exploits have been disclosed at the time of writing.
OpenCVE Enrichment
Debian DLA
Debian DSA