Impact
The vulnerability in the Linux kernel’s ACPI processor code allows an attacker to exploit improperly validated ACPI tables. The code previously parsed MADT and _MAT records without ensuring that the declared length of a record was fully contained within the available data. By injecting malformed or truncated ACPI tables, an attacker could cause the kernel to read or write outside the bounds of the intended data structure, potentially leading to a kernel crash, data corruption, or information disclosure. The flaw resides in the ACPI subsystem’s Ioapic entry handling and directly affects the integrity of kernel memory.
Affected Systems
This issue impacts systems running the Linux kernel, irrespective of distribution. Any machine that processes ACPI tables—typically x86 desktop or server hardware—could be affected if the kernel version lacks the patch commit referenced in the advisory. The correction applies to all current releases before the included patch, regardless of vendor RPM versioning, so administrators should verify their kernel version against the upstream kernel commit list.
Risk and Exploitability
The CVSS score of 7.3 reflects a high impact kernel bug. The EPSS score is reported as less than 1%, indicating a low probability of widespread real-world exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, and no public exploit has been disclosed. Attackers would need local access to inject malicious ACPI tables, possibly during system boot or through a compromised firmware update, making the attack vector relatively constrained and less likely to be used by the broader threat landscape.
OpenCVE Enrichment
Debian DLA
Debian DSA