Impact
The Linux kernel for C‑SKY ABIv2 incorrectly restores the fifth and sixth syscall arguments (a4 and a5) during the ptrace trace path. The code alters the stack pointer (sp) before reading these arguments from the pt_regs structure, which causes the values to be taken from the wrong offsets. As a result, any traced syscall that uses a4 or a5, such as mmap2 which requires six arguments, receives corrupted data. The corrupted arguments can cause the syscall to fail, leading to a traced child process exiting with an error code, effectively denying the traced workload its intended operation.
Affected Systems
Affected systems are Linux kernels that support C‑SKY ABIv2 instructions, including the ck860f board and kernel releases such as 4.19.15 and earlier versions that lack the patch. Any system that runs native or vendor‑supplied C‑SKY kernels and allows processes to be traced via ptrace is susceptible.
Risk and Exploitability
Risk and exploitability are low. Based on the description, the likely attack vector is local via ptrace, requiring local privilege to attach to target processes. The EPSS score is reported at less than 1 % and the vulnerability is not listed in the CISA KEV catalog. The impact is limited to disrupting the traced child rather than enabling arbitrary code execution or data exfiltration.
OpenCVE Enrichment
Debian DLA
Debian DSA