Impact
The Linux kernel has a flaw in software_node_get_reference_args() where the bounds check fails for an index value of UINT_MAX, causing an out-of-bounds read of the property array. This defect could expose kernel memory contents to a malicious actor, leading to confidentiality compromise. The CVSS score of 7 indicates a moderate severity vulnerability classified as a buffer over-read (CWE-119).
Affected Systems
All Linux kernel releases prior to the inclusion of the fix commit are affected. The issue is present in every vendor-supplied kernel that has not yet applied the patch, regardless of distribution or version.
Risk and Exploitability
The EPSS score of less than 1% suggests that exploitation is very unlikely under typical circumstances, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is from code that invokes software_node_get_reference_args() with an index of UINT_MAX, whether that code is part of the kernel itself or an in-kernel extension. While no direct privilege escalation path is documented, the resulting memory disclosure could eventually aid further attacks, and the out-of-bounds read could precipitate a crash or denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA