Impact
A flaw in the Linux kernel’s BPF interpreter for the LoongArch architecture incorrectly calculates jump offsets during JIT compilation. The legacy jmp_offset macro derived the distance from stale data, leading to wrong branch targets. When these erroneous branches are executed, the kernel can enter a soft‑lockup state, halting normal operation and causing a denial of service. The vulnerability is an arithmetic or calculation error that introduces an improper control flow.
Affected Systems
The issue arises in any Linux kernel build that includes the LoongArch BPF code path. No specific kernel release version was supplied, so any active kernel on a LoongArch system that has not incorporated the recent patch will be vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity impact. The EPSS score of <1% suggests that exploitation attempts are currently rare and the public exposure is limited. The vulnerability is not listed in the CISA KEV catalog, indicating it is not widely exploited in production environments. Attackers would need to supply a crafted BPF program that exercises the flawed JIT path, which is inferred to require local access or an entry point that allows user‑supplied BPF scripts such as via netfilter or eBPF sockets. Without broader public exploitation, the primary risk remains the stability impact on systems that run LoongArch‑targeted kernels.
OpenCVE Enrichment