Description
In the Linux kernel, the following vulnerability has been resolved:

csky: Fix a4/a5 restoration in syscall trace path

The syscall trace path reloads syscall arguments from pt_regs before
calling the syscall handler. On C-SKY ABIv2, the 5th and 6th syscall
arguments are prepared as stack arguments before invoking syscallid.

The current code adjusts sp before loading LSAVE_A4 and LSAVE_A5. Since
those offsets are relative to the original pt_regs base, loading them
after changing sp fetches the wrong slots. As a result, traced syscalls
that use the 5th or 6th argument may receive corrupted arguments.

This is visible with mmap2(), which takes six arguments. A small
PTRACE_SYSCALL reproducer opens a file and maps one page with:

mmap(NULL, 4096, PROT_READ | PROT_EXEC, MAP_PRIVATE, fd, 0)

Before the fix, the traced child fails the mmap and exits with 12.
After the fix, the mapping succeeds and the child exits with 0.

Fix the trace path by loading a4/a5 from pt_regs before changing sp.

Tested on: ck860f, linux-4.19.15, C-SKY abiv2
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Kernel
AI Analysis

Impact

The Linux kernel for C‑SKY ABIv2 incorrectly restores the fifth and sixth syscall arguments (a4 and a5) during the ptrace trace path. The code alters the stack pointer (sp) before reading these arguments from the pt_regs structure, which causes the values to be taken from the wrong offsets. As a result, any traced syscall that uses a4 or a5, such as mmap2 which requires six arguments, receives corrupted data. The corrupted arguments can cause the syscall to fail, leading to a traced child process exiting with an error code, effectively denying the traced workload its intended operation.

Affected Systems

Affected systems are Linux kernels that support C‑SKY ABIv2 instructions, including the ck860f board and kernel releases such as 4.19.15 and earlier versions that lack the patch. Any system that runs native or vendor‑supplied C‑SKY kernels and allows processes to be traced via ptrace is susceptible.

Risk and Exploitability

Risk and exploitability are low. Based on the description, the likely attack vector is local via ptrace, requiring local privilege to attach to target processes. The EPSS score is reported at less than 1 % and the vulnerability is not listed in the CISA KEV catalog. The impact is limited to disrupting the traced child rather than enabling arbitrary code execution or data exfiltration.

Generated by OpenCVE AI on September 19, 2026 at 09:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel that includes the C‑SKY a4/a5 restoration patch (or apply the corresponding patch from the kernel commit URLs provided).
  • If immediate upgrade is not possible, manually cherry‑pick the patch to the running kernel source, rebuild, and install the updated kernel.
  • After applying the patch or new kernel, test the ptrace syscall path by running a sample tracer that performs mmap2() to confirm that the child no longer fails with an error.

Generated by OpenCVE AI on September 19, 2026 at 09:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-703

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: csky: Fix a4/a5 restoration in syscall trace path The syscall trace path reloads syscall arguments from pt_regs before calling the syscall handler. On C-SKY ABIv2, the 5th and 6th syscall arguments are prepared as stack arguments before invoking syscallid. The current code adjusts sp before loading LSAVE_A4 and LSAVE_A5. Since those offsets are relative to the original pt_regs base, loading them after changing sp fetches the wrong slots. As a result, traced syscalls that use the 5th or 6th argument may receive corrupted arguments. This is visible with mmap2(), which takes six arguments. A small PTRACE_SYSCALL reproducer opens a file and maps one page with: mmap(NULL, 4096, PROT_READ | PROT_EXEC, MAP_PRIVATE, fd, 0) Before the fix, the traced child fails the mmap and exits with 12. After the fix, the mapping succeeds and the child exits with 0. Fix the trace path by loading a4/a5 from pt_regs before changing sp. Tested on: ck860f, linux-4.19.15, C-SKY abiv2
Title csky: Fix a4/a5 restoration in syscall trace path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:59.234Z

Reserved: 2026-09-17T16:02:15.090Z

Link: CVE-2026-93167

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:12.243

Modified: 2026-09-17T17:18:12.243

Link: CVE-2026-93167

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:45:17Z

Weaknesses
  • CWE-703

    Improper Check or Handling of Exceptional Conditions