Impact
The vulnerability resides in the LoongArch KVM driver of the Linux kernel. A stack variable, vector[], is declared in dmsintc_inject_irq() and may be utilized before it is initialized. An attacker could trigger this code path and cause unpredictable behavior, potentially corrupting memory or bringing the virtual machine under the KVM host to a non‑responsive state. The flaw does not directly expose secrets, but the erratic behavior can deny service to the affected virtual machine or host.
Affected Systems
The flaw affects all Linux kernel builds that include the LoongArch KVM code. Vendor information is listed as Linux:Linux. No specific kernel version range is documented in the CVE data; therefore, any kernel version containing the LoongArch KVM module could be susceptible.
Risk and Exploitability
The CVSS score of 7.3 indicates moderate to high severity. The EPSS score of less than 1% implies a very low overall probability of exploitation at the time of analysis. The vulnerability is not currently listed in the CISA KEV catalog. Attackers would need the ability to run code within the KVM host or control a guest that can trigger the uninitialized variable usage, making the attack vector likely local or requiring elevated privileges. No user‑directed exploitation vector is documented, so the threat is focused on hosts that run KVM on LoongArch platforms.
OpenCVE Enrichment