Impact
The Linux kernel contains code that translates USB string descriptors from UTF‑16 to UTF‑8. The translation routine expects a count of UTF‑16 code units, but the implementation mistakenly passes the raw byte count. This causes the routine to read past the end of the descriptor buffer whenever an odd or otherwise incorrect count is supplied. The result is an out‑of‑bounds read that can leak memory contents from the kernel space. The weakness is a classic out‑of‑bounds read (CWE‑125).
Affected Systems
The vulnerability resides in the UFS core driver for SCSI devices and affects all Linux kernel builds that include this code path prior to the patch commit. No specific kernel version range is listed, so every deployment of Linux that enables UFS SCSI support and runs a kernel built from the affected source tree is potentially vulnerable. All Linux distributions that ship such kernels remain in scope.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not in the CISA KEV list, indicating that while the flaw is technically exploitable, there is low evidence of active exploitation. An attacker would need to send a specially crafted SCSI request with a malformed string descriptor to a target device to trigger the buffer overread. This attack requires access to the SCSI device interface, so it is likely limited to local or compromised environments unless the SCSI subsystem is exposed over the network. No known private or public exploits have been reported.
OpenCVE Enrichment