Executive brief
A vulnerability in the Linux kernel's LoongArch architecture support could allow a local user to cause a system crash. The issue stems from how the system handles memory access errors within BPF programs, which are small scripts used for networking and monitoring. If an error occurs, the system may fail to recover properly, leading to a kernel panic and service disruption.
Technical details
A vulnerability exists in the LoongArch architecture's trap handling logic within the Linux kernel. Specifically, the 'do_ade()' function in 'arch/loongarch/kernel/traps.c' did not proactively call the common exception fixup routine for BPF-generated memory access errors (EX_TYPE_BPF). When a BPF program executes 'BPF_PROBE_MEM*' instructions that trigger an Address Error (ADE) exception, the lack of fixup handling prevents the kernel from safely recovering. A local attacker with the ability to load and run BPF programs could exploit this to trigger a kernel 'die' condition or a SIGBUS fault, resulting in a denial of service. Patches have been released for various stable branches including 6.6.y, 6.12.y, and 6.18.y.
Affected products
- Linux Linux Kernel 6.2 to 6.6.124, 6.7 to 6.12.70, 6.13 to 6.18.10, 6.19-rc1 to 6.19-rc3
Timeline
- 2025-12-31: other: Patch authored and signed off
- 2026-03-18: advisory: CVE published by kernel.org
- 2026-05-21: other: NIST initial analysis and CVSS assignment