Impact
The flaw arises when user supplied data is copied into a small, zero‑initialized stack buffer in the UFS driver without reserving space for the terminating NUL byte. If the input length exactly matches the buffer size, the single terminator is overwritten. The subsequent conversion to an integer via kstrtoint() then reads past the buffer boundary, which can cause a kernel panic or potentially expose adjacent kernel memory to a locally privileged user. The vulnerability does not provide remote code execution, but it can lead to a crash and loss of service.
Affected Systems
All Linux kernel binaries released before the embedded fix are affected, because the vendor is generic Linux and the product is the kernel itself. The CVE does not provide a specific version range, so any kernel that has not yet been patched to include the input‑length validation and terminator reservation is considered vulnerable. This includes all distributions that ship the unmodified UFS driver and expose the offending debugfs entry.
Risk and Exploitability
The EPSS score of less than 1 % indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is local via the debugfs interface, which typically requires root or elevated capabilities to write to the node. A local attacker who can write to the affected debugfs entry may trigger a kernel panic, resulting in a denial of service. The CVSS score is not explicitly provided, but the impact is sufficient to warrant prompt patching for systems that enable or rely on the debugfs functionality.
OpenCVE Enrichment
Debian DLA
Debian DSA