Impact
The flaw involves a stack over-read in the Linux kernel debug output helpers for the host1x GPU driver. When host1x_debug_output() or host1x_debug_cont() produce a string longer than 256 bytes, the length reported by vsnprintf() is incorrectly forwarded to the output sink, potentially causing a read that exceeds the bounds of the output buffer. A malicious actor could exploit this to read uncontrolled data from kernel memory, leading to information disclosure. The weakness is a classic buffer over-read, as recognized by CWE-179.
Affected Systems
Linux kernel implementations using the host1x GPU driver are affected. The vulnerability description does not specify particular kernel versions, so any release with this implementation before the applied fix is vulnerable.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KeV catalog. Exploitation would require local privileged access to the system’s debugfs interface, which is normally restricted. The vulnerability would not allow remote code execution or denial of service, but could expose sensitive kernel data to a privileged attacker. Given the low exploitation likelihood, monitoring for unusual debugfs activity and applying the kernel patch when available are recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA