Executive brief
A vulnerability in the Linux kernel's handling of memory access on PA-RISC architectures could allow a local user to bypass certain read protections. By using system calls, an attacker might access memory addresses that should normally be restricted. This could lead to system instability or unauthorized access to sensitive information within the operating system environment.
Technical details
A vulnerability exists in the Linux kernel's PA-RISC architecture support where the __get_user() macro fails to enforce read access protections. On PA-RISC, read access interruptions (code 26) are only triggered at privilege levels 2 and 3; because the kernel operates at privilege level 0, it bypasses these hardware checks. This allows a local attacker to use system calls to read from memory addresses that are otherwise protected from user-level access. The fix involves explicitly probing read access rights at privilege level 3 (PRIV_USER) using the 'proberi' instruction and returning -EFAULT if access is denied. Patches have been released for various stable kernel branches including 6.1, 6.6, 6.12, and 6.16.
Affected products
- Linux Linux Kernel v5.12+
Timeline
- 2025-09-05: disclosed: Initial publication of the CVE record.
- 2025-08-28: patched: Commits merged into stable kernel branches.
References
- https://git.kernel.org/stable/c/28a9b71671fb4a2993ef85b8ef6f117ea63894fe
- https://git.kernel.org/stable/c/4c981077255acc2ed5b3df6e8dd0125c81b626a9
- https://git.kernel.org/stable/c/741b163e440683195b8fd4fc8495fcd0105c6ab7
- https://git.kernel.org/stable/c/89f686a0fb6e473a876a9a60a13aec67a62b9a7e
- https://git.kernel.org/stable/c/f410ef9a032caf98117256b22139c31342d7bb06
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html