Impact
The Linux kernel bug around the arm64 process context switch caused the SCTLR_EL1.TCSO0 flag, used for MTE store‑only tag checking, to be omitted from the user mask. As a result, when a context switch occurs the flag is never cleared, and the value leaks into the next task. This leakage can expose fine‑grained memory tag information or other privileged state to a task that should not see it, effectively allowing information disclosure between user space processes or between processes with different privilege levels. The flaw is a classic register or state leakage issue, commonly known as an information exposure weakness (CWE‑200).
Affected Systems
All Linux kernels running on arm64 architecture with MTE store‑only tag checking enabled are affected. The vendors listed are the Linux kernel maintainers. No specific kernel version or release is enumerated in the advisory, so any kernel before the inclusion of the patch in the mainline should be considered vulnerable.
Risk and Exploitability
Based on the description, it is inferred that the EPSS score is less than 1 %, indicating a very low likelihood that this vulnerability has been exploited in the wild. The vulnerability is not listed in the CISA KEV catalogue. The CVSS score is not provided, but the local nature of the flaw combined with the potential for data leakage implies a moderate overall risk. Exploitation requires that an attacker can run or influence both the victim process and the malicious process on the same system. The advisory recommends applying the patch immediately to prevent any potential leakage.
OpenCVE Enrichment