Impact
The Linux kernel’s Dell WMI base driver contains a flaw where the ultra performance key is indexed incorrectly. Because the event data is already parsed, the driver uses a wrong index and can read past the end of the supplied buffer. This buffer overread could expose kernel memory contents to an attacker, potentially allowing information disclosure or assisting further local privilege escalation. No remote code execution path is described, but the vulnerability could leak sensitive data from the kernel space.
Affected Systems
This issue affects the Linux kernel on x86 platforms that include the Dell WMI driver before the commit that added the index check. Version information is not specified in the advisory, so any kernel build that incorporates the old Dell WMI module is considered vulnerable. The problem applies broadly to Linux distributions running on Dell hardware that expose the WMI interface to the kernel.
Risk and Exploitability
The EPSS score is below 1%, suggesting a very low likelihood of exploitation, and the bug is not in the CISA KEV catalog, meaning no confirmed public exploits exist. The attack requires local access to the system’s Dell WMI interface, so the vector is local rather than remote. While the vulnerability could reveal kernel memory, turning that into a full compromise would need additional steps, so the overall risk is moderate, but urgent patching is advised.
OpenCVE Enrichment