Impact
The bug occurs in the Linux kernel’s LoongArch KVM code when the memory region flags are changed with the KVM_MR_FLAGS_ONLY operation. The kernel fails to copy architecture‑specific flags from the old memory slot into the new one, causing the arch.flags to be zero. This missing flag means that huge‑page support checks are bypassed, allowing the kernel to map guest pages to incorrect host pages during read faults. An attacker who can make the KVM memory region flags change—for example by toggling KVM_MEM_LOG_DIRTY_PAGES during live migration—can force the guest to read or write user‑space or kernel memory outside its allocated region, potentially leading to privilege escalation or arbitrary code execution on the host.
Affected Systems
Affected systems are all Linux kernel builds running on LoongArch CPUs that use the KVM hypervisor. The vulnerability manifests only in kernels that have not received the patch changes referenced in the provided kernel commit URLs. No specific kernel version range is listed, so any current release that has not yet been updated is vulnerable.
Risk and Exploitability
The CVSS score is 8.8, showing a high‑severity flaw, but the EPSS score is below 1 % and the vulnerability is not yet listed in the CISA KEV catalog, indicating that exploitation is unlikely but still possible. The attack requires privileged access to the KVM configuration or the ability to trigger a KVM_MR_FLAGS_ONLY operation, which is typically available only to the host administrator or trusted virtual machine manager processes. As a result, the risk is primarily to administrators or attackers who can compromise the host, rather than to end‑user guests.
OpenCVE Enrichment
Debian DLA
Debian DSA