Impact
A flaw in the arm64 Linux kernel causes the value of the original first syscall argument (orig_x0) to become unsynchronized with the actual argument (x0) when a traced process is stopped on a syscall entry after a SECCOMP_RET_TRACE event. This allows a ptrace tracer that has the necessary privileges to silently alter the first argument of a syscall that is subjected to a seccomp filter, thereby bypassing security policies that are intended to restrict that argument. The effect is a trusted process being able to subvert user‑level security controls without triggering audit or seccomp checks, which can lead to privilege escalation or other severe compromises.
Affected Systems
All arm64 Linux kernels falling within the Linux:Linux vendor scope that have not yet incorporated the fix identified by commit e057b9477232. The patch was merged after the initial intention in commit 88b839ce497c but was incomplete until the later change, so any kernel prior to that commit remains affected. Specific version ranges are not listed, but all builds lacking the described update should be regarded as vulnerable.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, while the EPSS score of <1% means exploitation is considered unlikely at present; however, the vulnerability is not in the CISA KEV catalog, suggesting no confirmed widespread use yet. An attacker would need to run as a ptrace tracer (e.g., as root or with CAP_SYS_PTRACE) and target a process protected by seccomp. If successful, the attacker can modify syscall arguments bypassing filter checks, potentially leading to system compromise. Applying the kernel fix removes the state inconsistency and restores integrity of seccomp enforcement.
OpenCVE Enrichment