Impact
The imx6q cpufreq driver in the Linux kernel allocates an array of voltage entries for each ARM OPP during probe, but it uses a static counter that is never reset. When a second bind occurs after an unbind, the counter continues from its previous value, writing past the newly allocated array’s end and overflowing one 32‑bit element. This out‑of‑bounds write corrupts kernel memory, allowing an attacker who can trigger consecutive probe cycles to overwrite arbitrary kernel addresses and potentially gain elevated privileges or execute arbitrary code. The description indicates that an attacker would need the ability to rebind the driver, which typically requires local access to sysfs or the device tree – this is inferred as the attack vector.
Affected Systems
Systems running the Linux kernel with the imx6q cpufreq driver are affected. The vulnerability is present in any kernel version before the commits referenced in the CVE description. No specific kernel releases are listed, so all implementations that load this driver prior to the patch are potentially impacted.
Risk and Exploitability
The flaw is a classic out‑of‑bounds write (CWE-119/CWE-787). Exploitation requires the ability to bind and unbind the driver more than once, which typically requires local access to device tree or sysfs nodes. The EPSS score is less than 1 % and the issue is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation, yet the severity of the potential kernel corruption warrants prompt patching. It is not explicitly stated that remote exploitation is possible; the information suggests that local privileges are required.
OpenCVE Enrichment
Debian DLA
Debian DSA