Executive brief
A function in the Linux kernel's RISC-V architecture code can cause a kernel crash (page fault) when a cleanup operation unmaps memory regions while the function is still running in a background thread. This can occur if the background operation is delayed—for example, by debug activity in the system firmware—leading to system instability and denial of service.
Technical details
The vulnerability exists in the vec_check_unaligned_access_speed_all_cpus() function, which is marked with the __init attribute but runs asynchronously in a kernel thread to probe unaligned memory access performance via SBI calls. The __init marker causes the kernel to free the function's code from the .init.text section after boot (via free_initmem()), but if the kthread is still running at that time—particularly if SBI calls are slow or blocked—the kthread attempts to execute freed code, resulting in a page fault and kernel oops. The fix is to remove the __init annotation so the function code remains mapped throughout the system's lifetime. No user-mode interaction or special privileges are required; the fault occurs during normal kernel operation on RISC-V systems.
Affected products
- Linux Linux Kernel up to 7.0.0 (RISC-V architecture)