Executive brief
A vulnerability in the Linux kernel's MIPS architecture support can cause the system to crash when certain background tasks or testing tools are running. This occurs because the system incorrectly attempts to access memory information that does not exist for these specific tasks. An exploit would result in a denial-of-service (system crash), potentially disrupting operations or causing data loss on affected MIPS-based devices.
Technical details
A NULL pointer dereference exists in arch/mips/kernel/process.c within the mips_stack_top() function. The vulnerability occurs because the code attempts to dereference current->thread.abi to calculate VDSO and GIC page offsets without verifying if the ABI pointer is initialized. While standard user processes have an associated ABI, kernel threads (kthreads) and certain tasks initiated by KUnit do not, leading to a kernel panic when stack_top() is called. This is a local vulnerability that can be triggered by tasks that lack an ABI or vDSO mapping. Patches have been released across multiple stable kernel branches to add the necessary NULL check.
Affected products
- Linux Linux Kernel 4.14.77 to 4.15, 4.18.15 to 4.19, 4.19.1 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-06-11: patched: Initial patch authored by Thomas Weißschuh
- 2025-09-04: disclosed: CVE published
References
- https://git.kernel.org/stable/c/24d098b6f69b0aa806ffcb3e18259bee31650b28
- https://git.kernel.org/stable/c/5b6839b572b503609b9b58bc6c04a816eefa0794
- https://git.kernel.org/stable/c/82d140f6aab5e89a9d3972697a0dbe1498752d9b
- https://git.kernel.org/stable/c/ab18e48a503230d675e824a0d68a108bdff42503
- https://git.kernel.org/stable/c/bd90dbd196831f5c2620736dc221db2634cf1e8e
- https://git.kernel.org/stable/c/cddf47d20b0325dc8a4e57b833fe96e8f36c42a4
- https://git.kernel.org/stable/c/e78033e59444d257d095b73ce5d20625294f6ec2