Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability exists in the Linux kernel's handling of BPF kfunc calls on LoongArch architecture. The issue arises because these native calls do not properly follow the LoongArch calling conventions, leading to potential kernel panics. The vulnerability affects several versions of the Linux kernel.
The vulnerability can cause a kernel panic, disrupting system operations and potentially leading to a denial of service.
To reproduce this vulnerability, invoke a BPF kfunc call on a LoongArch system without the proper sign extension of the call arguments. This can be done by creating a BPF program that calls a kfunc and deploying it on a LoongArch Linux kernel version prior to the patch.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.