Impact
The kyro overlay driver in the Linux kernel performs viewport coordinate calculations using 32‑bit unsigned arithmetic. When large input values are supplied, the intermediate calculations wrap around before the results are passed to SetOverlayViewPort(). Because the driver does not verify that the adjusted coordinates fit into the 16‑bit hardware register fields, this wraparound can cause invalid register values to be written. The resulting kernel memory corruption could lead to incorrect graphics state or potentially alter kernel execution behavior.
Affected Systems
This vulnerability affects the Linux kernel’s fbdev kyro overlay driver. All kernel versions that include the kyro driver and do not incorporate the patch that validates viewport coordinates are potentially vulnerable. No specific kernel release is listed, so any kernel using the kyro functionality is at risk until the driver is updated or disabled.
Risk and Exploitability
The EPSS score is less than 1 % and the flaw is not listed in CISA’s KEV catalog, indicating that widespread exploitation has not been observed. However, the vulnerability can be triggered by providing large viewport dimensions to the SetOverlayViewPort() call, which typically requires privileged access to the graphics subsystem. A local privileged attacker could exploit the integer wraparound to corrupt kernel memory, resulting in high potential impact on confidentiality, integrity, and availability. Given the low EPSS and lack of known exploitation, the overall risk is moderate but remediation is strongly recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA