Impact
This vulnerability arises when the Linux ARM kernel is compiled with PREEMPT_RT enabled but the option HAVE_POSIX_CPU_TIMERS_TASK_WORK is left disabled. The result is that CPU timers expire in hard IRQ context, causing the run_posix_cpu_timers routine to acquire the task sighand->siglock while in an invalid sleeping state. This triggers a BUG condition and can lead to a kernel panic or system hang, thereby impacting availability.
Affected Systems
The flaw affects all Linux kernel builds that support ARM architectures and are compiled with the PREEMPT_RT patchset. Specifically, any kernel configuration that enables PREEMPT_RT yet fails to select HAVE_POSIX_CPU_TIMERS_TASK_WORK is vulnerable. The issue is present in generic Linux kernels for ARM, including ARM64 and ARM32, and would apply to hosted environments such as KVM when ARM32 host support is present, but that support was removed in later commits.
Risk and Exploitability
The CVSS severity is not explicitly provided, but the nature of the bug—kernel panic from sleeping in interrupt context—is a high‑severity flaw. The EPSS score is less than 1%, indicating low probability of exploitation in the wild, and the vulnerability is not listed in CISA KEV. The likely attack vector would require privileged access to trigger CPU timers under PREEMPT_RT, such as via a setrlimit(RLIMIT_CPU) abuse or by eliciting timer_create calls. However, due to the contextual requirement and the low EPSS, immediate remediation is advised rather than relying on detection of exploit attempts.
OpenCVE Enrichment