Impact
The flaw in the arm_pmuv3 perf driver allowed a hardware identifier field to be passed to userspace without being initialized. Based on the description, it is inferred that a userspace process that reads perf sample data could receive residual kernel memory. Because the field could contain garbage or sensitive data, an attacker could gather unintended information. The patch zero‑initializes the field, which also protects future extensions. This vulnerability is a data disclosure issue rather than an execution or denial of service flaw, so it does not directly compromise system control.
Affected Systems
The vulnerability affects any Linux kernel build that includes the arm_pmuv3 branch‑record brute‑force (BRBE) component and that exposes PERF_SAMPLE_BRANCH_HW_INDEX to userspace. It is inferred that no specific distribution versions are listed, so any kernel version prior to the patch may be vulnerable. Systems without arm_pmuv3 support or that disable BRBE are not impacted.
Risk and Exploitability
The EPSS score of less than 1% indicates that exploitation is considered unlikely; the vulnerability is not listed in the CISA KEV catalog. It is inferred that an attacker would need to read perf sample data from a privileged or otherwise acceptable userspace context, meaning the attack surface is limited. Because the disallowed data is simply garbage, the impact is mostly limited to exposing unused memory contents rather than secret values or code execution. Consequently, the overall risk is low, though it merits remediation to avoid inadvertent information leaks.
OpenCVE Enrichment