Impact
A RISC‑V KVM guest can trigger an out‑of‑bounds read and write by issuing a PMU EVENT_GET_INFO request with an excessively large event count. The 32‑bit input is multiplied by the size of an event entry; on 64‑bit RISC‑V the product overflows, truncating a 64‑bit value. KVM allocates a single entry but then loops over the original, large count, causing kernel memory corruption. This buffer‑overflow flaw, identified as CWE‑787, can allow a malicious guest to overwrite host kernel control data and therefore can lead to elevated privileges or remote code execution on the host kernel.
Affected Systems
All Linux kernel releases that include the standard KVM module compiled for 64‑bit RISC‑V hardware are affected. The vulnerability is present in the kernel KVM virtualization stack for RISC‑V, regardless of the specific kernel minor version. Users running Linux kernels with enabled PMU event handling for virtual machines on RISC‑V should review their deployment and apply the available patch.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1 % suggests a low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, implying no known active exploits. Nonetheless, a guest VM with direct access to the host’s PMU interface can trigger the out‑of‑bounds condition, enabling local privilege escalation or remote code execution on the host kernel.
OpenCVE Enrichment