Executive brief
A vulnerability exists in the Linux kernel's virtualization component (KVM) for LoongArch systems. An issue in how the system handles internal processor communications could allow a local attacker to cause a system crash or potentially gain unauthorized access. This affects the stability and security of virtualized environments running on LoongArch hardware.
Technical details
A buffer overflow exists in the send_ipi_data() function within the LoongArch KVM implementation (arch/loongarch/kvm/intc/ipi.c). The vulnerability is caused by passing a 4-byte buffer (uint32_t) to kvm_io_bus_read(), while underlying emulation functions like loongarch_ipi_readl() perform 8-byte writes due to sign extension. When CONFIG_STACKPROTECTOR is enabled, this results in a kernel panic due to stack corruption. A local attacker with access to the guest environment could potentially exploit this to crash the host kernel or achieve privilege escalation. The issue has been resolved by increasing the buffer size to 8 bytes (uint64_t) and explicitly limiting the I/O bus operations to 4 bytes.
Affected products
- Linux Linux Kernel 6.13 to 6.16.4, 6.17-rc1, 6.17-rc2
Timeline
- 2025-08-20: patched: Initial fix commit 5c68549c81bcca70fc464e305ffeefd9af968287
- 2025-09-05: disclosed: CVE-2025-39704 published