Impact
The vulnerability arises when the Linux kernel allocates an output buffer for a CXL mailbox command without limiting the size to the payload size. An attacker can request a command that specifies a very large out.size value, causing the kernel to allocate an excessively large buffer. If the allocation exceeds INT_MAX, the kernel issues a warning, taints the system, and if panic_on_warn is enabled, the kernel will panic. This results in a denial of service that brings the entire system offline. The weakness is an uncontrolled memory allocation that is not validated against the maximum payload size.
Affected Systems
Linux kernel releases, with no specific version information provided in the advisory. The issue applies to all builds that include the cxl/mbox mailbox code path.
Risk and Exploitability
The EPSS score is less than one percent, indicating that known exploitation activity is rare. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires the ability to send a CXL command with a crafted large out.size value, which typically implies local privilege or a compromised kernel module. While the risk of successful exploitation is low, the impact is high because a single panic can crash the kernel. The likely attack vector is a local privileged attacker or an attacker who can control a CXL device driver.
OpenCVE Enrichment
Debian DLA
Debian DSA