In the Linux kernel, the following vulnerability has been resolved:
parisc: Clear stale IIR value on instruction access rights trap
When a trap 7 (Instruction access rights) occurs, this means the CPU couldn't execute an instruction due to missing execute permissions on the memory region. In this case it seems the CPU didn't even fetched the instruction from memory and thus did not store it in the cr19 (IIR) register before calling the trap handler. So, the trap handler will find some random old stale value in cr19.
This patch simply overwrites the stale IIR value with a constant magic "bad food" value (0xbaadf00d), in the hope people don't start to try to understand the various random IIR values in trap 7 dumps.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Feb 27, 2024 |
| Huawei Euleros 2_0_sp10 | — | Upgrade kernel-tools-libsUpgrade kernelUpgrade python3-perfUpgrade kernel-toolsUpgrade kernel-abi-stablelists | May 13, 2024 | Feb 27, 2024 |
| Huawei Euleros 2_0_sp8 | — | Upgrade kernel-toolsUpgrade python-perfUpgrade perfUpgrade python3-perfUpgrade kernel-headersUpgrade kernelUpgrade kernel-develUpgrade bpftoolUpgrade kernel-tools-libs | Jul 23, 2024 | Feb 27, 2024 |
| Huawei Euleros 2_0_sp9 | — | Upgrade python3-perfUpgrade kernelUpgrade kernel-toolsUpgrade kernel-tools-libs | Jul 17, 2024 | Feb 27, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 27, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub