Executive brief
A vulnerability in the Linux kernel's LoongArch architecture support could allow a local user to cause a system hang or 'soft lockup.' This issue occurs within the BPF subsystem, which is used for high-performance networking and system monitoring. An exploit could disrupt system availability and operations, requiring a reboot to recover.
Technical details
A vulnerability exists in the LoongArch BPF JIT compiler (bpf_int_jit_compile) due to incorrect jump offset calculations during tail calls. An extra pass in the JIT compilation process skips context initialization, leaving the 'out_offset' variable at its default value of -1. This results in the generation of negative jump offsets in the final assembly, leading to infinite loops or 'soft lockups' when specific BPF programs are executed. The issue is triggered during the execution of BPF tail calls on LoongArch systems. Patches have been released across multiple stable kernel branches to correctly calculate the instruction offsets.
Affected products
- Linux Linux Kernel 6.1 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-09-04: advisory: NVD Published Date
- 2025-08-28: patched: Kernel stable tree commits applied
References
- https://git.kernel.org/stable/c/17c010fe45def335fe03a0718935416b04c7f349
- https://git.kernel.org/stable/c/1a782fa32e644aa9fbae6c8488f3e61221ac96e1
- https://git.kernel.org/stable/c/9262e3e04621558e875eb5afb5e726b648cd5949
- https://git.kernel.org/stable/c/cd39d9e6b7e4c58fa77783e7aedf7ada51d02ea3
- https://git.kernel.org/stable/c/f2b5e50cc04d7a049b385bc1c93b9cbf5f10c94f
- https://git.kernel.org/stable/c/f83d469e16bb1f75991ca67c56786fb2aaa42bea
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html