Impact
The Linux kernel DRM bridge driver for the tc358767 device incorrectly trusts the controller‑reported AUX read size. After clamping the requested size, the driver later adopts the controller’s byte count without bounds checking, resulting in a 256‑byte read into a 16‑byte stack buffer. This flaw can corrupt kernel stack memory, potentially compromising system stability and integrity.
Affected Systems
Linux kernel, all releases prior to the application of the tc358767 AUX size clamp patch. No specific vendor or version list was provided beyond the generic "Linux kernel" label. System administrators should verify that the kernel image in use incorporates the relevant patch, which can be found in the upstream commit referenced in the advisory.
Risk and Exploitability
The EPSS score indicates an exploitation probability of less than 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low current threat level. However, as the fault resides in kernel code, any successful exploitation would affect the kernel stack and could lead to system compromise. The likely attack vector is local: an attacker with the ability to drive the drm/bridge subsystem can initiate the vulnerable AUX transfer sequence. Because the driver performs no input validation on the controller’s reported byte count, the flaw remains exploitable until the patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA