Impact
The MVIY_PERCPU() macro in the s390 architecture expands C string literals into a GNU as macro invocation that older binutils versions collapse into a single argument, causing the macro to silently fail. The mviy instruction is omitted, leaving the per‑CPU sequence unmarked in lowcore. When an exception returns after a CPU migration the per‑CPU register cannot be restored, which can trigger a kernel crash or denial of service. This flaw is a CWE‑88 weakness and does not allow direct code execution that bypasses the kernel. The issue arises in kernels compiled with binutils versions earlier than 2.39, which drop separating whitespace between quoted macro arguments during input scrubbing, causing the compiler to produce malformed assembly.
Affected Systems
All Linux kernel builds that use the default binutils toolchain (version 2.30) or any older binutils when compiling the s390 architecture. Because the MVIY_PERCPU macro expands only when compiled against binutils older than 2.39, any kernel compiled with such toolchains will fail to emit the mviy instruction, leading to per‑CPU register issues during CPU migration. This applies to all modern Linux distributions that compile their kernel from source using a legacy toolchain.
Risk and Exploitability
The CVSS score of 7.0 reflects medium severity, while the EPSS score of < 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Inferred from the description, exploitation would require local‑root privileges, the ability to rebuild the kernel with an older binutils compiler, or control over the build environment. Consequently, the risk is limited to environments that rebuild the kernel with a legacy toolchain and perform CPU migration events, rather than remote attackers targeting running systems.
OpenCVE Enrichment