Impact
The Linux kernel’s LoongArch KVM implementation does not validate MSI data before passing it to the EIOINTC interrupt controller. MSI data, supplied by a guest VM through ioctl calls such as KVM_SET_GSI_ROUTING or KVM_SIGNAL_MSI, is interpreted as an interrupt index without bounds checking. When the supplied value exceeds the 256‑interrupt range, the code performs out‑of‑bounds writes to kernel memory structures, potentially corrupting the kernel and allowing an attacker to execute arbitrary code with kernel privileges. This flaw is a classic input‑validation and out‑of‑bounds write weakness.
Affected Systems
The vulnerability exists in the Linux kernel source for the LoongArch architecture. Any kernel build on LoongArch that includes KVM MSI routing and has not incorporated the patch series referenced in the advisory is affected. No specific release versions are enumerated in the CVE data.
Risk and Exploitability
With a CVSS score of 8.8 the flaw is of high severity, while the EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker must be able to create or control a KVM guest and issue the relevant ioctl calls to /dev/kvm. Once that condition is met, the attacker can supply an MSI number outside the valid range, inducing kernel memory corruption. Attack requires local or VM‑level access and can result in privilege escalation or VM‑escape, but it does not rely on network exposure.
OpenCVE Enrichment