Impact
The flaw arises from missing validation in the DRM panthor driver that allows a user process to request a vm_bind mapping whose address range can overlap the carve‑out region reserved for kernel buffer objects. Because the kernel does not check for this overlap, a malicious actor could create a mapping that touches kernel memory used by driver objects, potentially corrupting data or writing to privileged memory. In addition the code previously permitted arithmetic overflow of the 64‑bit mapping range, which could also lead to unexpected behaviour. As described, no immediate exploit path is detailed, but the unchecked overlap and overflow together raise the possibility of memory corruption that could be leveraged for privilege escalation.
Affected Systems
All Linux kernel builds that ship the panthor DRM driver in an unpatched state are affected. The vulnerability is kernel‑level and vendor independent, so any distribution running a kernel prior to the patch that contains this driver code must be considered vulnerable. No specific version range is provided; all susceptible builds before the fix are included.
Risk and Exploitability
The EPSS score is below 1%, indicating an overall low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, via the privileged drm_gpuvm_bind ioctl, and would require a user process with the ability to invoke this ioctl to craft overlapping mappings. Although the advisory does not describe a proven exploit, the unchecked overlap and potential integer overflow create a plausible avenue for memory corruption and possibly privilege escalation if the attacker can manipulate the mapping range.
OpenCVE Enrichment