Impact
The Linux kernel crypto subsystem’s async request cloning routine incorrectly copies only the stack‑sized portion of the request structure, ignoring space required for the async provider’s context. When a provider such as Intel QAT accesses the unallocated area through acomp_request_ctx, it writes past the end of the allocated memory, triggering a slab out‑of‑bounds write detected by KASAN. This flaw can corrupt kernel memory, enabling an attacker to execute arbitrary code or crash the system.
Affected Systems
All Linux kernel releases that include the vulnerable crypto acomp implementation are affected; the vendor listing simply references Linux. Specific affected versions are not enumerated in the data, but the patch implementing the fix is present in the kernel source as commit 889fa17a0af09ff93a9166abc82ee7a654faa49b. System administrators should check if their running kernel includes that commit before a full upgrade.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. Based on the description, it is inferred that an attacker would need to trigger the async crypto provider path, which typically requires local system access and a suitable crypto workload, so the attack vector is local. The EPSS score is reported as less than 1%, indicating a very low likelihood of widespread exploitation at the present time and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Nonetheless, because this is a kernel buffer overrun that can lead to local privilege escalation, the risk to systems that expose the affected crypto subsystem is significant. No public exploit is currently known, but the high severity of the bug warrants prompt mitigation.
OpenCVE Enrichment