Impact
The flaw arises in the Linux kernel’s ARM implementation when a user‐mode program triggers an unhandled fault via the bkpt instruction. The fault handlers do_DataAbort() and do_PrefetchAbort() do not enable interrupts before calling force_sig_fault(), leaving the processor in a state where interrupts are disabled during signal delivery. This can cause the kernel to stall or misbehave, effectively denying service to the affected system or applications.
Affected Systems
All ARM‑based Linux kernel builds that include the default exception handling code and have CONFIG_PERF_EVENTS disabled are impacted. The issue applies to the Linux kernel as a whole; specific version ranges are not listed, so any kernel that has not applied the patch is potentially affected.
Risk and Exploitability
The EPSS score is below 1 %, indicating that the likelihood of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog, and it requires a local user program to execute bkpt to trigger the fault. Because it is a kernel‑level bug that can cause a system halt or loss of responsiveness, the CVSS severity, while not provided, would be high if assessed. Given the low exploitation probability and the requirement for a local user program, the overall risk is moderate to low, but the potential impact of denial of service justifies prompt remediation.
OpenCVE Enrichment