Impact
The vulnerability arises from the Linux kernel's handling of system calls on PowerPC architectures. When seccomp or ptrace set a custom return value via syscall_set_return_value, the kernel was expected to honor that value. However, due to improper sentinel handling in system_call_exception, the code incorrectly treated the sentinel as a system‑call‑range overflow and returned –ENOSYS, overwriting the intended result placed in the registers. This flaw could mislead applications that rely on accurate syscall return codes, potentially causing denial of service or logic errors in security‑critical code.
Affected Systems
The flaw affects all versions of the Linux kernel running on PowerPC machines prior to the commit that introduces a thread flag for explicit return values. Both 32‑bit and 64‑bit variants are impacted. No other architectures are mentioned, and no specific kernel releases are listed in the data.
Risk and Exploitability
The advisory lists an EPSS score of less than 1 % and notes that the vulnerability is not in CISA's KEV catalog, indicating a low likelihood of targeted exploitation in the wild. Nevertheless, the defect allows a privileged attacker or an attacker with the ability to manipulate seccomp or ptrace (e.g., through a memory corruption vulnerability) to corrupt the error reporting path, leading to abnormal program termination or denial of service. Because the flaw resides in the kernel, it requires a patch to achieve a robust fix.
OpenCVE Enrichment