Impact
A kernel fault in remoteproc caused the client firmware to use a signed 32‑bit integer where an unsigned value was required. A crafted offset such as 0xFFFFFFF0 turns into -16, which the code then promotes to a large unsigned size_t during arithmetic. This permits the driver to read a header structure 16 bytes before the legitimate buffer, exposing kernel memory or crashing the driver. The fix stores the offset as an unsigned 32‑bit value and validates it with unsigned comparisons before any pointer calculation, eliminating the overflow path.
Affected Systems
All Linux kernel builds that include the remoteproc subsystem are impacted until they have applied the patch that introduced the unsigned handling. No specific vendor or version list is supplied, but any system executing kernel code prior to commit 0d385be8f199b349f325cf90584b47b6a044ea79 is vulnerable.
Risk and Exploitability
The EPSS score is below 1 %, and the vulnerability is not listed in the CISA KEV catalog, indicating a low to moderate exploitation probability. The attack requires a firmware image with a crafted signed offset for a device that loads firmware via remoteproc. An attacker could potentially cause a crash or read sensitive kernel data, but would need to supply malicious firmware to the target. Overall risk remains relatively low, yet the attack surface exists in embedded or IoT devices where firmware updates are performed without stringent validation.
OpenCVE Enrichment
Debian DLA
Debian DSA