Impact
The vulnerability occurs when the Linux kernel processes a UDF symlink containing a partially‑specified pathComponent header. The udf_symlink_filler function passes this incomplete header to udf_pc_to_char without verifying that a complete header remains in the buffer. This causes an out‑of‑bounds read of kernel memory, potentially exposing sensitive data. The weakness is an input validation flaw that can be classified as a CWE‑839 scenario.
Affected Systems
All Linux systems that use the kernel’s UDF file‑system support are affected. The specific kernel versions are not enumerated in the data, so any system with the UDF module present prior to the rapid patch should be considered vulnerable until the fix is applied.
Risk and Exploitability
The EPSS score is indicated as < 1 %, implying a very low probability of exploitation today. The vulnerability is not listed in CISA’s KEV catalog. No exploit is publicly known. The attacker would need to supply a crafted UDF volume containing a malformed symlink, which could be achieved on systems that mount external media or allow local file system writes. The risk is primarily for confidentiality, with no direct denial of service or privilege escalation indicated. The absence of a CVSS score limits the quantitative assessment, but the nature of the OOB read still warrants prompt patching.
OpenCVE Enrichment
Debian DLA
Debian DSA