Description
In the Linux kernel, the following vulnerability has been resolved:

ARM: 9481/2: breakpoint: CFI breakpoints only on demand

This removes the stub hw_breakpoint_cfi_handler() from ARM, making
it not steal breakpoint type 0x03 (ARM_ENTRY_CFI_BREAKPOINT) unless
CFI is actively used in the kernel.

When not instrumenting with CFI, or when a breakpoint is issued in
userspace, we fall through to return 1 from hw_breakpoint_pending()
"unhandled fault" so userspace can make use of this breakpoint.

Tested with LKDTM and this command line:
echo CFI_FORWARD_PROTO > /sys/kernel/debug/provoke-crash/DIRECT
still works as expected.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Fault Handling Failure
Action: Assess
AI Analysis

Impact

A flaw in the ARM hardware breakpoint handler in the Linux kernel permits the kernel to treat a breakpoint type 0x03 (ARM_ENTRY_CFI_BREAKPOINT) as an unhandled fault unless Control‑Flow Integrity (CFI) is actively used. The patched code removes the stub hw_breakpoint_cfi_handler, preventing it from stealing this breakpoint type. If the legacy stub remains, an attacker that can influence breakpoint settings may cause the kernel to incorrectly handle a fault, potentially leading to a denial of service or kernel panic. The underlying weakness is an improper restriction of operations within a privileged context.

Affected Systems

All ARM‑based Linux kernel installations that include the legacy breakpoint handler and have not applied the commit that removed hw_breakpoint_cfi_handler are affected. The vulnerability is present in any kernel before the patch, regardless of version, so any server or device running an ARM variant of the Linux kernel compiled with the default configuration may be vulnerable until the kernel is updated.

Risk and Exploitability

The EPSS score is reported as less than 1% and the vulnerability has not been listed in CISA’s KEV catalog, indicating a very low probability of widespread exploitation. The absence of a published CVSS score limits precise severity measurement, but the flaw involves kernel fault handling rather than remote code execution. Based on the description, the likely attack vector is local privilege escalation or a kernel module that can set custom breakpoints; this conclusion is inferred from the vulnerability details. Therefore the overall risk can be considered low, yet the kernel‑critical nature of this area warrants review.

Generated by OpenCVE AI on September 19, 2026 at 04:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel update that removes the hw_breakpoint_cfi_handler stub, which is the official fix.
  • Disable CFI instrumentation during boot by omitting CFI‑related boot options. This mitigation is inferred from the description and has not been officially documented.
  • Restrict access to debugfs and related crash‑debugging interfaces to privileged accounts only, limiting the ability of an attacker to manipulate breakpoint settings from userspace.

Generated by OpenCVE AI on September 19, 2026 at 04:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 14:30:00 +0000


Sat, 19 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-730

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ARM: 9481/2: breakpoint: CFI breakpoints only on demand This removes the stub hw_breakpoint_cfi_handler() from ARM, making it not steal breakpoint type 0x03 (ARM_ENTRY_CFI_BREAKPOINT) unless CFI is actively used in the kernel. When not instrumenting with CFI, or when a breakpoint is issued in userspace, we fall through to return 1 from hw_breakpoint_pending() "unhandled fault" so userspace can make use of this breakpoint. Tested with LKDTM and this command line: echo CFI_FORWARD_PROTO > /sys/kernel/debug/provoke-crash/DIRECT still works as expected.
Title ARM: 9481/2: breakpoint: CFI breakpoints only on demand
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:15:22.727Z

Reserved: 2026-09-11T19:38:34.800Z

Link: CVE-2026-90306

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:28.263

Modified: 2026-09-21T14:17:28.903

Link: CVE-2026-90306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T05:00:09Z

Weaknesses