Impact
The vulnerability resides in the Linux kernel’s BPF subsystem on the s390 architecture. A missing register clear occurs when a read‑modify‑write (RMW) atomic operation that performs a fetch faults over an unmapped arena page. The exception handler writes into the probe entry but leaves the register that should hold the fetched value unchanged; it retains whatever stale data was in that register before the atomic operation. This flaw means that a BPF program could observe or propagate arbitrary register contents instead of the expected zero or fresh data, which could lead to incorrect BPF execution or, if the stale data contains sensitive information, unintended data leakage. The weakness corresponds to improper initialization of a register (CWE‑665).
Affected Systems
Affected systems are Linux kernel deployments compiled for the s390 (s390x) platform that have not yet incorporated the patch referenced in the commits linked above. Since the patch removes the register‑clear bug, any kernel revision prior to the commit that introduced the fix is considered vulnerable. No specific vendor product versions were listed, so the risk applies to all s390 Linux kernels before the patch.
Risk and Exploitability
The EPSS score for this vulnerability is reported as less than 1 %, indicating a very low estimated likelihood of exploitation in the current environment. The vulnerability is not listed in CISA’s KEV catalog. It is inferred from the description that exploitation requires the ability to load or compile BPF programs that perform atomic fetch operations; therefore, a local attacker with sufficient privileges or capabilities would be needed to trigger the fault path. No public exploits are known. Given the low EPSS score and the privilege requirements, the overall risk is assessed as low, but it could be higher in environments with permissive BPF loading policies.
OpenCVE Enrichment