Linux Kernel Cros Ec Chardev Ioctl Data Leak Vulnerability

Vulnerability

A vulnerability in the Linux kernel's Chrome platform component, specifically within the Cros EC character device, has been addressed. This vulnerability allowed for a kernel data leak through the ioctl interface by manipulating the 'insize' parameter in the 'cros_ec_command' structure. The issue arose because larger 'insize' values could be used to access and read unintended kernel memory. The vulnerability has been fixed by ensuring that the memory used is properly zeroed before being utilized.

Impact

Exploitation of this vulnerability could lead to unauthorized access to kernel memory, allowing for potential information leaks or exposure of sensitive data.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.