Impact
The flaw lies in the ljca_enumerate_gpio() function of the Linux kernel USB driver. The function reads a bank_num value supplied by an attached USB device and uses it to write into a two‑element array called valid_pin[]. The code checks that the reply length matches the expected struct size and that pins_per_bank multiplied by bank_num does not exceed the maximum number of GPIO pins, but it does not verify that bank_num fits into the two‑element array. When an attacker supplies a bank_num of nine, the loop writes nine 32‑bit words into the array, overflowing the stack and corrupting control data. This buffer overflow is a classic stack corruption that could lead to arbitrary code execution or system crash, compromising confidentiality, integrity, or availability. The vulnerability corresponds to CWE‑121.
Affected Systems
The defect exists in the Linux kernel for all vendor builds that include the ljca USB driver. Any operating system running an affected kernel version is a potential target. The issue is not limited to a specific distribution but applies to any Linux kernel that has not yet been patched for this change. Custom or older kernel builds are also at risk. The vulnerability requires physical access to the USB port; remote exploitation over the network is not possible.
Risk and Exploitability
The EPSS score is reported as less than 1%, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the lack of bounds checking allows a malicious device to overflow the stack, which could lead to arbitrary code execution if an attacker can physically attach a forged LJCA device. The absence of a publicly published CVSS score means operators cannot rely on a numeric severity gauge, but the potential for serious compromise makes the risk high if an attacker controls the USB device.
OpenCVE Enrichment
Debian DLA
Debian DSA