Impact
A buffer overflow occurs in the Linux kernel’s ACPI parser for GICC entries when the get_logical_index() function returns an error value that is not checked. The unchecked return allows a malformed IAFFID entry to index a per_cpu variable array out of bounds, corrupting kernel memory and potentially enabling elevated code execution or system crash. The vulnerability is strictly a kernel‑level issue and can be leveraged only within a local environment where an attacker can influence the ACPI tables seen by the kernel at boot or runtime.
Affected Systems
All Linux kernel releases that contain the unpatched gic_acpi_parse_iaffid path are affected. The specific affected versions were not enumerated in the advisory; any version of the kernel before the commit that added the return‑value check is vulnerable.
Risk and Exploitability
The CVSS score of 8.4 signals a high‑severity flaw, while the EPSS score of less than 1% indicates that the likelihood of exploitation in the wild is low at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply malicious ACPI tables or firmware to trigger the overflow, so the practical attack vector is local control; remote exploitation is not supported by the information provided. The patch introduces a defensive check, reducing the risk by preventing the out‑of‑bounds access.
OpenCVE Enrichment