Impact
The kernel function cxlctl_get_feature creates a buffer whose size is based on a user‑supplied out_len value and then writes a separate user‑controlled count of bytes into that buffer. Because count is not limited by an overrun of the allocated heap buffer, resulting in an out‑of‑bounds write that corrupts kernel memory. This could potentially allow a local attacker with access to the CXL device to gain higher privileges or execute arbitrary code at the kernel level.
Affected Systems
The defect is present in the Linux kernel as supplied by the vendor Linux:Linux. No specific kernel version range is cited by the CNA, so the vulnerability may exist in any kernel that includes the unguarded cxlctl_get_feature path before the commit that introduces the guard against the overflow.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate‑to‑high severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a local user who can invoke cxlctl on a CXL device and supply both out_len and count values. Given the local‑only prerequisite and the specific conditions needed to overflow the buffer, the risk is mainly of local privilege escalation or kernel data corruption, with a low probability of widespread impact under current conditions.
OpenCVE Enrichment