Impact
A flaw was discovered in the Linux Kernel USB ATM driver where the ci_range structure is initialized with the sentinel value ATM_CI_MAX (–1). When the kernel uses the vpi_bits and vci_bits fields as bit shift amounts, the negative value causes a shift‑out‑of‑bounds error and invokes UBSan. This undefined behavior can trigger a kernel crash and is therefore a vector for denial of service. The description includes a UBSan warning and a stack trace demonstrating the out‑of‑bounds shift, but does not indicate successful exploitation for code execution.
Affected Systems
Any system running a Linux Kernel that includes the usbatm driver and does not incorporate the recent commit changes. The issue affects all versions where the ci_range initialization is still set to the ATM_CI_MAX sentinel, as identified in the kernel source branches held by the Kernel maintainers.
Risk and Exploitability
The EPSS score is listed as < 1 %, indicating a very low probability of exploitation at the time of analysis. The vulnerability is not currently listed in CISA’s KEV catalog. Because the flaw requires the kernel to load the usbatm module and the attacker would need local or privileged access to trigger the shift error, the practical attack surface is limited. Nevertheless, the undefined behavior could lead to unplanned system crashes and loss of availability in environments where the ATM driver is actively used.
OpenCVE Enrichment
Debian DLA
Debian DSA