Impact
The vulnerability exists in the Linux kernel’s kho module. The function kho_preserved_memory_reserve() calculates the size of a left shift on the constant 1: 1 << (order + PAGE_SHIFT). Since the '1' is a 32-bit integer, shifting it more than 31 bits causes undefined behavior. For preserved regions larger than 2 GiB the shift mis‑computes the size, potentially leading to memory corruption or a kernel crash. The flaw is catalogued as CWE‑1335.
Affected Systems
All Linux kernel builds that contain the unpatched kho module are affected. or branch; therefore the impact applies generically to any kernel version that still uses the original calculation. Because the bug can be triggered by allocating preserved memory larger than 2 GiB – for example via kho_preserve_pages() or the memblock reserve_mem API – any system that may request such a reservation is potentially vulnerable. The exact scope depends on the kernel configuration and the ability to request large preserved regions.
Risk and Exploitability
The CVSS score of 4.4 rates the vulnerability as low severity. Its EPSS score is below 1 %, indicating a small chance of exploitation in the wild, and it is not on the CISA KEV list. An attacker requiring local privileged code with kernel‑mode access could trigger the bug by requesting a preserved region that exceeds 2 GiB, which may the kernel. Remote exploitation appears unlikely without kernel‑level privileges.
OpenCVE Enrichment