Impact
The flaw involves the load_unaligned_zeropad() routine in the Linux kernel for s390 architecture. When an unaligned eight‑byte read crosses a page boundary, the routine may generate a secure storage access exception. The exception handler for donated secure‑storage pages fails to recover from such a case, triggering an endless loop of repeated exceptions that never resolves. The result is a kernel‑level denial of service where the system can become unresponsive or crash. The weakness corresponds to an improper handling of exceptional conditions that can lead to uncontrolled resource consumption.
Affected Systems
Vendors: Linux (kernel). All kernel releases that include the load_unaligned_zeropad() function on s390 architecture are affected. No specific version information is provided, so any kernel that has not yet incorporated the revert and proper fix is potentially impacted.
Risk and Exploitability
The CVSS score is 5.5, indicating moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating it has not been widely exploited. Attackers would need a privilege level that allows them to trigger the secure storage access exception, such as kernel or privileged user mode. Based on the description, it is inferred that the likely attack vector is a local privilege escalation or a malicious kernel module, as the defect resides in kernel memory‑access handling.
OpenCVE Enrichment
Debian DLA
Debian DSA