Impact
The vulnerability in the Linux kernel's speakup accessibility module allows an out‑of‑bounds write to the letter_offsets array during help_init() when a function name is overridden via sysfs with a first character outside the a–z range. The flaw can corrupt kernel memory, leading to a denial of service or other unintended kernel behavior. The impact is limited to kernel execution context and can manifest as a fatal error or a bleep sound when the exploit triggers.
Affected Systems
Linux kernel systems where the speakup module is enabled. Any kernel that includes the vulnerable speakup implementation is affected; no specific version range is listed in the advisory.
Risk and Exploitability
The EPSS score is below 1%, indicating a low probability of exploitation at this time, and the vulnerability is not listed in CISA's KEV catalog. The fix requires root write access to /sys/accessibility/speakup/i18n/function_names, so the likely attack vector is a local privilege escalation or an attacker already running as root. Despite the low exploitation probability, the kernel memory corruption could allow an attacker to compromise the system if exercised.
OpenCVE Enrichment
Debian DLA
Debian DSA