Impact
The flaw lies in the LoongArch rethook trampoline, which incorrectly preserves the $r21 register that holds the CPU’s per‑CPU base address. When a task migrates to another core while the trampoline is executing, the stale $r21 value is restored, poisoning the register on the new core. This leads to accesses to incorrect per‑CPU data structures, corrupting the scheduler, timers, and RCU paths, and can cause hard lockups under heavy kretprobe usage. The vulnerability does not currently allow arbitrary code execution, but it results in critical system instability and denial of service. The weakness can be classified as improper initialization of a critical register.
Affected Systems
All Linux kernels running on LoongArch architecture are potentially affected, with the issue demonstrated on a Loongson‑3A6000 platform. The impact is triggered when kretprobes are heavily used (e.g., file‑system paths) under a pre‑emptible load. No vendor‑specific product list exists beyond the generic Linux:Linux identification.
Risk and Exploitability
The CVSS score of 7.8 marks this flaw as high severity. The EPSS score is below 1 %, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. Attackers would need to execute code that triggers heavy kretprobe activity, such as installing large amounts of software or performing extensive file operations, to induce the fault. Under those conditions the kernel can lock up, denying service to all users on the affected system.
OpenCVE Enrichment
Debian DLA
Debian DSA