Impact
In the Linux kernel on s390 machines, the BPF "ly" instruction fails to zero the upper 32 bits of a 64‑bit BPF register when loading a 32‑bit cpu_nr. The subsequent replacement instruction llgf correctly zeros the upper bits, but the unpatched code leaves garbage data in the high part of BPF_REG_0. This register corruption can cause BPF programs to behave unpredictably or incorrectly, potentially leading to system integrity problems or denial of service.
Affected Systems
It is inferred that all Linux kernel releases for the s390 architecture that have not applied the patch replacing "ly" with "llgf" are affected. This includes the mainline kernel and distribution kernels that contain the unpatched code. No specific version range is given, so any kernel containing the unmodified instruction is vulnerable.
Risk and Exploitability
The CVSS score of 7.8 marks the issue as High severity, yet the EPSS score of < 1 % indicates a very low probability of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the ability to load a custom BPF program into the kernel; therefore, only systems that permit untrusted BPF loading pose the greatest risk. Because the flaw resides in the bpf interpreter, it is unlikely to provide privilege escalation, but the corrupted register can affect the logic of BPF programs and potentially disrupt kernel operations.
OpenCVE Enrichment