Impact
The flaw resides in the Linux kernel’s KVM module for the s390 architecture, where an unsigned 64‑bit field that represents a watchpoint size is stored in a 64‑bit integer and later copied into a signed 32‑bit integer without adequate bounds checking. The code performs a bounds check on the truncated 32‑bit value but uses the original 64‑bit length for memory allocation. This mismatch means a malicious user can request allocations larger than 4 GB, causing the kernel to attempt an oversized allocation that exceeds the MAX_PAGE_ORDER limit, triggering a WARN and potentially leading to kernel degradation and a local denial of service.
Affected Systems
The affected product is the Linux kernel running KVM on s390 systems. All kernel releases prior to the patch that introduced the length check are vulnerable. The fix targets the __import_wp_info() routine that processes watchpoint imports from user space.
Risk and Exploitability
The EPSS score indicates a very low likelihood of exploitation (<1 %). The vulnerability is not listed in CISA KEV, suggesting no publicly known exploits. The likely attack vector is through KVM’s watchpoint import interface, requiring the ability to send crafted watchpoint lengths from user space. Because the failure manifests as a WARN and not a direct crash or code execution, the immediate risk is a local denial of service rather than remote code execution. Nonetheless, patching remains the recommended response to eliminate potential instability.
OpenCVE Enrichment
Debian DLA
Debian DSA