Impact
The Linux kernel SCSI UFS subsystem had a flaw where the connected lane count, used as an index into arrays sized by UFS_MAX_LANES, was not validated against zero or values exceeding the supported range. This oversight allowed an attacker that could influence the lane count value to cause the kernel to access memory outside the intended bounds, potentially leading to a crash, memory corruption, or unintended information disclosure. The issue is reflected by CWE-125 and CWE-787 weaknesses in array index handling.
Affected Systems
All Linux kernel deployments that contain the unpatched UFS core code are affected. The vulnerability does not specify an exact kernel version, so any system running an earlier kernel build before the applied patch is part of the risk scope.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability that this vulnerability will be actively exploited, and it is not listed in the CISA KEV catalog. The attack vector requires local access to a UFS device, typically necessitating privileged interaction with the SCSI subsystem or a compromised driver. While the overarching risk is mitigated by the low exploit likelihood, the potential for system instability or denial of service warrants prompt attention.
OpenCVE Enrichment