Impact
A kernel driver function that handles virtual device traffic incorrectly treats a negative pull count as a large positive size, causing an oversized copy in the receive path. This integer conversion can corrupt kernel memory and can trigger a kernel panic or crash, leading to a denial of service on the affected host.
Affected Systems
All Linux kernel builds that include the vdpa_sim_net driver before the fix are affected. The vulnerability is present in any release that still ships the buggy code and has not applied the official patch, regardless of distribution or version number.
Risk and Exploitability
There is currently no publicly known exploit for this bug and the EPSS score is not available, so the empirical likelihood of exploitation is uncertain. However, because the flaw operates in kernel mode, a successful exploit could lead to kernel memory corruption and a system crash. The CVSS score is unknown, but the lack of a KEV listing does not diminish the risk of a local or privileged attacker repeatedly triggering crashes. Administrators should treat the situation as a moderate to high risk until the latest patched kernel is deployed.
OpenCVE Enrichment