Impact
The vulnerability is located in the LoongArch BPF implementation of the Linux kernel, where the stack layout incorrectly places the optional arena register slot above the tail call counter (tcc) context. When the arena_vm_start feature is enabled, this placement shifts the relative offset of the tcc_ptr slot, causing hardcoded tracking macros to no longer match the actual layout. The resulting misalignment can lead to memory corruption, including misaligned or overwritten data on the stack.
Affected Systems
This bug affects any instance of the Linux kernel running on LoongArch processors that includes the BPF stack layout with the arena register slot above the tcc context. No specific kernel versions are listed, but the issue applies wherever the arena_vm_start feature is enabled and the stack frame follows the described layout.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. The attack vector is inferred to be local, requiring execution of malicious BPF programs with the arena_vm_start feature enabled. Because the bug causes memory corruption, a successful exploit could result in kernel stability problems or denial of service, but the absence of known exploits and the low EPSS suggest a moderate immediate risk that can be mitigated by applying the available kernel patch.
OpenCVE Enrichment