Impact
In the Linux kernel, the ublk subsystem has a flaw where the import_ubuf() function can fail if the user‑space address range provided by the ublk server is outside the allowed user address space. The fault path returns 0 bytes copied on failure but still passes an uninitialized iov_iter struct to ublk_copy_user_pages(), resulting in undefined behavior. This can cause the kernel to copy garbage data or crash, leading to memory corruption, unintended data disclosure, or denial of service.
Affected Systems
All Linux kernels with enabled ublk support are potentially affected. No specific release is enumerated, so any kernel that compiles with ublk should be considered vulnerable until the patch is applied.
Risk and Exploitability
The CVSS score is 7.8, reflecting a moderate to high severity. The EPSS score is below 1%, indicating a low exploitation probability. It is not listed in CISA’s KEV catalog. The vulnerability is likely exploitable by a local user who has access to the ublk driver, such as someone who can control the ublk server process or send crafted requests to the ublk device. The attack would require local privileges but could lead to kernel memory corruption and system compromise if successful.
OpenCVE Enrichment