Impact
The vulnerability occurs when the Linux arm64 kernel handles EFI runtime services with software PAN enabled. During a voluntary preemption, the fpsimd context switch is performed after the TTBR0_EL1 page‑table change, leaving the kernel with an incorrect translation table pointer. This allows the kernel to dereference user memory addresses incorrectly, causing a kernel oops and potential loss of confidentiality, integrity or availability, and opening a path for privilege escalation.
Affected Systems
Affected systems are Linux kernel builds for arm64 that enable EFI runtime services and have the CONFIG_ARM64_SW_TTBR0_PAN setting enabled. No specific version numbers are listed, but the issue applies to any arm64 kernel containing the described fpsimd/context‑switch code path.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not in CISA KEV, indicating a low likelihood of widespread exploitation at present. However, the effect is severe: a kernel crash or escalation can be achieved by a user process, making the impact potentially critical. The likely attack vector is through normal user‑land execution on an impacted kernel, exploiting the improper preemption behavior during EFI calls.
OpenCVE Enrichment