Impact
An attacker can inject interrupts while the Safe-RET mitigation runs on systems that use the SRSO Safe-RET feature, causing the safe return sequence to be prematurely neutralized. The result is that the kernel may speculatively execute unintended paths, leaking sensitive data from kernel memory to an attacker. The weakness is a control‑flow integrity defect (CWE‑201) that facilitates speculative information exposure.
Affected Systems
All Linux kernel implementations that enable the SRSO Safe-RET mitigation, regardless of distribution. The issue exists in kernels that have not applied the Safe‑RET patch referenced in the commit logs.
Risk and Exploitability
The CVSS score is 8.8 and no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires a local attacker with privileged access to inject interrupts during the Safe‑RET execution window, a capability available in many elevated privilege contexts. The potential impact is high due to possible data leakage, though widespread exploitation has not yet been reported.
OpenCVE Enrichment