Impact
In RV64 Linux kernels, the BPF JIT compiler failed to sign‑extend 1‑byte and 2‑byte signed arguments passed to kernel functions, causing them to be interpreted incorrectly. An attacker who can load crafted BPF code could make kernel functions receive malicious values, potentially leading to unintended execution paths or privilege escalation. The weakness is a type‑conversion flaw, specifically improper conversion or interpretation of data (CWE‑681).
Affected Systems
Linux kernel running on RISC‑V 64‑bit processors (RV64). The issue applies to all kernel releases prior to the commit that added correct sign‑extension; no specific version list is provided, so any unpatched RV64 kernel is potentially vulnerable.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating a low likelihood of exploitation. Exploitation would require the ability to load a BPF program that uses signed one‑ or two‑byte arguments in a kfunc call, suggesting a local or privileged attacker scenario. The CVSS score is not provided, but the lack of exploitation evidence and the specialized attack surface imply a moderate to low overall risk.
OpenCVE Enrichment
Debian DLA
Debian DSA