Impact
The Linux kernel sensorhub ring handler contains a buffer overread flaw that occurs when ChromeOS EC firmware responds with fewer bytes than expected. The kernel copies into a buffer larger than the data received, resulting in a memory overread that can expose adjacent kernel memory contents. The vulnerability is a classic read buffer overread (CWE‑125).
Affected Systems
All Linux kernel builds that include the sensorhub driver used by ChromeOS systems are affected, as the CNA lists Linux:Linux and the CPE string covers the kernel. No specific version range is supplied; therefore any kernel prior to the patch that contains the unmodified sensorhub ring handler is considered vulnerable.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity. The EPSS score of <1% shows that exploitation is unlikely in the near term, and the flaw is not present in the CISA KEV catalog. The overread would be triggered by sending malformed EC commands or by compromising the EC firmware, implying a limited attack vector that requires interaction with ChromeOS EC firmware. No confirmed exploit is known. Overall the risk is moderate, with low to moderate exploitability.
OpenCVE Enrichment
Debian DLA
Debian DSA