Impact
The Linux kernel’s coresight ETM (Embedded Trace Macrocell) driver contains a loop that calculates an index using the expression (nrseqstate - 1). When the hardware register TRCIDR5.NUMSEQSTATE is 0b000, this calculation underflows, producing a large unsigned value that can index outside the intended array bounds. The resulting out‑of‑bounds write can corrupt kernel memory, potentially allowing an attacker with sufficient local privileges to gain elevated privileges or cause a denial of service. The weakness is a classic integer underflow that leads to an unsafe use of an array index. The likely attack vector is inferred to be a local attacker with the ability to execute code with kernel privileges, such as via a malicious module.
Affected Systems
All Linux kernel releases that contain the unpatched coresight ETM driver are affected. The vulnerability exists in every vendor’s Linux kernel that has not incorporated the commit 1674d9bff8073bdee5dbc200f56fc3caa28d0566 or later.
Risk and Exploitability
The EPSS score is below 1%, and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of exploitation in the wild. Nevertheless, because the flaw occurs in kernel space, a local attacker who can execute code with kernel privileges—such as by loading a malicious module—could potentially exploit the integer underflow. The likely attack vector is inferred to be local privileged code execution, as the vulnerability is within kernel space and requires code that can write kernel memory. Theoretical impact is high (kernel memory corruption), but current exploit likelihood remains low.
OpenCVE Enrichment
Debian DLA
Debian DSA