Impact
The vulnerability arises from the Cros EC Type‑C driver in the Linux kernel copying power‑delivery capability descriptors supplied by the embedded controller into a fixed array of seven entries. The driver reads the descriptor count directly from the EC and uses it in a memcpy without checking against the array size. If the EC reports more than seven descriptors, the memcpy overruns the stack buffer, corrupting adjacent kernel data and potentially causing a kernel crash.
Affected Systems
The flaw resides in the Linux kernel Cros EC Type‑C driver. Devices that load this driver—such as ChromeOS kernels or Linux derivatives that use the same embedded‑controller interface—are affected. No specific kernel version range is listed in the CVE data, so any unpatched kernel containing this driver should be considered vulnerable.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity. The EPSS score of <1% suggests that exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalog. The CVE description does not specify how an attacker might manipulate the EC’s PD capability count. It is inferred that exploiting this flaw would require tampering with the embedded controller firmware or influencing its responses, which may be possible with physical or firmware‑level access. Without a confirmed exploit path, the actual risk depends on an attacker’s ability to alter the EC behavior.
OpenCVE Enrichment
Debian DLA
Debian DSA