Impact
The Linux kernel defect in the riscv‑sbi‑mpxy mailbox interface causes the SBI return value to dictate how many bytes are copied from shared memory into the RPMI notification buffer without first validating that this length is within the negotiated shared‑memory size. Because the event walker uses a reversed loop condition, it can read a partial event record that exceeds the bounds of the copied notification. This unchecked length leads to a buffer overflow within the kernel, which can crash the system or corrupt memory, resulting in a denial‑of‑service condition. The weakness originates from failing to validate external input and is related to CWE‑20 and CWE‑119.
Affected Systems
All Linux kernel releases that deploy the riscv‑sbi‑mpxy mailbox interface are potentially affected. The vendor product in question is the Linux kernel itself; specific affected versions are unspecified in the advisory, so all distributions running Linux on RISC‑V hardware that include this interface may be vulnerable until patched.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity vulnerability. Although the EPSS score is below 1 % and the issue is not listed in the CISA KEV catalog, the weakness can be exploited by any user able to inject malformed RPMI notifications into the shared‑memory region used by the mailbox. Because the mutation occurs in kernel space, the requisite attack vector is local and requires privilege or the ability to influence the mailbox content. The low exploitation probability suggests this is not a widely leveraged attack, but the potential for a critical denial‑of‑service makes a timely patch important.
OpenCVE Enrichment