Executive brief
A vulnerability in the Linux kernel for systems using the PA-RISC architecture could allow a local user to bypass certain memory protections. Specifically, the system fails to properly check read permissions when performing certain low-level synchronization operations. This could potentially be used by an attacker to cause a system crash or interfere with memory that should be restricted.
Technical details
A vulnerability exists in the PA-RISC architecture's implementation of Light-Weight Syscall (LWS) gateway calls in the Linux kernel. The kernel uses 'ldw' and 'stbys,e' instructions to trigger memory reference interruptions; however, because the kernel and gateway page execute at privilege level 0, read access interruptions (which only trigger at levels 2 and 3) are never generated. This allows user-space code to execute LWS compare-and-swap operations on memory addresses that should be read-protected at the user privilege level (PRIV_USER). The fix introduces explicit 'proberi' instructions to verify read access rights at privilege level 3 before proceeding with the operation.
Affected products
- Linux Linux Kernel 5.12 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4
Timeline
- 2025-09-05: disclosed
- 2025-09-05: advisory
References
- https://git.kernel.org/stable/c/8bccf47adbf658293528e86960e6d6f736b1c9f7
- https://git.kernel.org/stable/c/9b6af875baba9c4679b55f4561e201485451305f
- https://git.kernel.org/stable/c/bc0a24c24ceebabb5ba65900e332233d79e625e6
- https://git.kernel.org/stable/c/e8b496c52aa0c6572d88db7cab85aeea6f9c194d
- https://git.kernel.org/stable/c/f6334f4ae9a4e962ba74b026e1d965dfdf8cbef8
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html