Impact
The Linux kernel GRU TLB miss handler performs page table walks during interrupt context without acquiring page-table locks or retaining a reference to the accessed page. It also uses a kernel-mode page-table accessor on user page tables. This defect allows a locally privileged attacker to induce a TLB miss that triggers the unsafe walk, potentially reading or corrupting page table entries. The result can be arbitrary memory corruption or privilege escalation. The root issue is an improper synchronization of shared kernel data (CWE 362).
Affected Systems
All Linux kernel releases that ship the GRU driver and its TLB miss handler before the commits referenced in the advisory are affected. This includes every version of the kernel that has not yet incorporated the fix that removes the direct walker and replaces it with a polling mode handler. Even are at risk if they contain the vulnerable code.
Risk and Exploitability
The CVSS score of 7.8 marks this flaw as high severity, and the EPSS score of less than 1% indicates that automated exploitation is uncommon. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread attacks. Exploitation requires triggering a TLB miss in an interrupt context, so the attack vector is kernel-level and would normally demand local or elevated privileges. Based on the description, the attack is likely of medium complexity but could lead to severe compromise if achieved.
OpenCVE Enrichment
Debian DLA
Debian DSA