Impact
cxl_get_feature reads a feature in a loop but incorrectly passes a fixed output size for each iteration, causing the buffer to overflow when a device returns more data than expected on a partial pass. The overflow corrupts kernel memory, which can lead to arbitrary code execution with kernel privileges. The vulnerability is a classic buffer overflow that directly compromises the confidentiality, integrity, and availability of the system.
Affected Systems
The flaw exists in the Linux kernel’s cxl/features implementation. No specific kernel versions are listed, so any kernel containing this code path and enabling CXL support is potentially vulnerable until the patch is applied. Users of CXL‑enabled devices on any Linux distribution should consider their systems affected.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low probability of initial exploitation. However, the impact of a successful exploit is high, and the flaw can be triggered by interacting with a CXL device that returns oversized data. Attackers would need to target a specific device or environment; the vector is likely local or remote depending on device access.
OpenCVE Enrichment