Linux Kernel Arm64 User-Execution Never Set Vulnerability in Swapper Page Tables

Vulnerability

A vulnerability in the Linux kernel's arm64 architecture has been addressed, concerning the user-execution never (UXN) setting on swapper page tables. Systems implementing FEAT_EPAN were affected because read/write access to the idmap was improperly allowed, leading to kernel panics when certain idmap KPTI flags were accessed. The issue arose because UXN was not applied to the swapper page table entries, allowing unauthorized access. The vulnerability has been resolved by correctly setting the UXN on these entries.

Impact

The vulnerability could cause kernel panics, disrupting system operations and potentially leading to denial of service conditions.

Added: Jun 18, 2025, 12:49 PM
Updated: Jun 18, 2025, 12:49 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.