Impact
The vulnerability was a kernel bug in the USB image driver for the MDC800 device. The driver allocated buffers with kmalloc() that were not zero‑initialized. When a shorter USB message arrived, leftover bytes from the previous allocation could remain in the buffer, leaking kernel stack contents. This could provide an attacker with sensitive internal data, leading to information disclosure.
Affected Systems
Any Linux system using the default kernel with the usb_mdc800 driver before the patch is affected. All distributions that ship the kernel version containing the bug – according to the CPE, linux_kernel.* – are potentially impacted until they apply the fix.
Risk and Exploitability
The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a low but not negligible chance of exploitation. The attack requires local or physical access to the USB MDC800 device and the ability to inject crafted messages; it does not provide remote code execution or privilege escalation. The patch that changes kmalloc() to kzalloc() eliminates the leak entirely.
OpenCVE Enrichment
Debian DLA
Debian DSA