Impact
The flaw exists in the LoongArch implementation of kprobes. When a user‑level process issues a breakpoint instruction with code 11, the handler pretends a probe is running and calls preempt_enable_no_resched() without a matching preempt_disable(). This underflows the current task’s preempt count and temporarily reports the task as running in interrupt context. The side effect is that sockets allocated during a SIGTRAP handler are assigned to the root control group instead of the calling process’s group, allowing them to bypass BPF_CGROUP_INET_SOCK_CREATE policy checks. The vulnerability is a local logic fault that could be exploited to gain elevated privileges or bypass network policies when a user can trigger a breakpoint.
Affected Systems
All Linux kernel builds running on LoongArch CPUs are affected, including all mainstream distributions that ship the default kernel for that architecture. Version information is not explicitly listed, but the issue was present in mainline kernels before the recent commit that restores the proper probing check.
Risk and Exploitability
The CVSS score of 7.8 categorises the vulnerability as high severity, while the EPSS score of < 1% indicates a very low current exploitation probability. The issue is not listed in the CISA KEV catalog. Exploitation requires a local user that can execute arbitrary instructions, mainly by setting up a breakpoint 11. An attacker could trigger the underflow to seduce the kernel into treating the task as an interrupt, thereby creating sockets in the root cgroup and evading BPF cgroup policies. This provides a privilege escalation path from a regular user to kernel‑level effect in the context of the affected architecture.
OpenCVE Enrichment
Debian DLA
Debian DSA