Impact
An error in the RISC‑V BPF implementation causes the kernel stack to be corrupted when tailcall jumps are executed while the CFI Clang policy is enabled. The stray instruction skips a stack pointer adjustment, resulting in a corrupted stack that can lead to arbitrary memory corruption. Based on the description, attackers who can inject or control BPF programs may exploit this bug to corrupt kernel memory, potentially escalating privileges or crashing the system.
Affected Systems
This flaw affects all Linux kernel builds that enable CONFIG_CFI_CLANG on RISC‑V architectures. No specific upstream version numbers are provided, but any kernel incorporating the vulnerable tailcall path is impacted. The issue was fixed in recent commits referenced above; therefore, kernels before those commits are susceptible.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity. However, the EPSS score of less than 1% suggests a low likelihood of exploitation at this time, and the vulnerability is not included in CISA’s KEV catalog. Based on the description, a likely attack vector involves supplying a malicious BPF program, implying that a local or privileged attacker could potentially trigger the corruption. Patch status is urgent given the potential for kernel compromise.
OpenCVE Enrichment