Impact
The vulnerability is a buffer overflow in the acpi_package_ids array used by the LoongArch architecture when a virtual machine is configured with many sockets. The array was sized to accommodate fewer packages than a LoongArch VM can expose, allowing a PPTT ACPI table to overflow the bounds of the array. The overflow can corrupt kernel memory, potentially leading to a denial of service or privilege escalation if an attacker can influence the ACPI data presented to the kernel.
Affected Systems
All Linux kernel builds that support the LoongArch architecture are affected, including mainstream distributions that ship the kernel for this architecture. The issue manifests when a virtual machine is configured with one core per socket and a maximum of 256 sockets (packages) per VM on the LoongArch virt platform with PPTT ACPI tables. Version information is not explicitly listed but any kernel that compiles for LoongArch and processes PPTT tables without the patch is vulnerable.
Risk and Exploitability
The CVSS score of 8.4 classifies the flaw as high severity, indicating serious potential damage. The EPSS score is below 1 %, suggesting that the probability of exploitation in the near term is low; however, the flaw is not listed in the CISA KEV catalog. The likely attack vector involves an attacker having control over the virtual machine configuration or the ACPI tables supplied to the kernel, allowing an overflow that could compromise the guest operating system. Because kernel memory corruption can lead to arbitrary code execution or system crash, the impact is significant if exploitation occurs.
OpenCVE Enrichment
Debian DLA
Debian DSA