Impact
The mis‑ordered teardown path in the LoongArch KVM driver causes per‑CPU kvm_context structures and associated callbacks to be allocated before the generic kvm_init() routine is called. If kvm_init() fails, the driver never calls kvm_loongarch_env_exit(), leaving those resources allocated and ultimately exhausting kernel memory or other per‑CPU resources. The consequence is a local denial of service through resource depletion, potentially forcing the kernel to use swap or crash if the leak persists. This flaw is a classic resource leak and could be classified as CWE‑401.
Affected Systems
All Linux kernel builds that include the LoongArch KVM module and run LoongArch processors. The vulnerability is present in any kernel configuration where the kvm_loongarch_init() code path is compiled in, regardless of the specific kernel version, until the fix is applied.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low likelihood of exploitation. The bug manifests only when the KVM module is loaded or the kernel is rebooted, so it requires privileged boot or module loading capabilities. Therefore the risk is primarily local and limited to systems that run LoongArch hardware with KVM enabled.
OpenCVE Enrichment
Debian DLA
Debian DSA