Impact
The vulnerability is found in the Linux kernel’s BPF subsystem for RISC‑V, where the handling of an atomic load_acquire operation incorrectly skips adding an exception table entry. This omission causes a faulting PROBE_ATOMIC load_acquire to trigger a kernel oops. In addition, when the fault occurs the stale register value is not cleared, and the verifier still believes the load overwrote it, potentially allowing that register content to leak through a map to user space. The flaw is local and requires execution of a BPF program, but it can result in a kernel crash and disclosure of internal register data.
Affected Systems
All Linux kernel installations running on RISC‑V hardware that use the BPF verifier for load_acquire operations are affected, up to the commit that fixed the extable handling bug. The issue resides in the kernel’s BPF component, so all distributions shipping an unpatched RISC‑V kernel are potentially exposed. No specific kernel version numbers are provided in the data, but any release prior to the fix commit is impacted.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating overall low likelihood of exploitation at present. Based on the description, the likely attack vector is local: an attacker who can load a malicious BPF program—typically requiring elevated privileges or a kernel escape—can trigger the fault. This could lead to a local denial of service by crashing the kernel or exposing sensitive register contents to user space.
OpenCVE Enrichment