In the Linux kernel, the following vulnerability has been resolved:
arm64: cacheinfo: Fix incorrect assignment of signed error value to unsigned fw_level
Though acpi_find_last_cache_level() always returned signed value and the document states it will return any errors caused by lack of a PPTT table, it never returned negative values before.
Commit 0c80f9e165f8 ("ACPI: PPTT: Leave the table mapped for the runtime usage") however changed it by returning -ENOENT if no PPTT was found. The value returned from acpi_find_last_cache_level() is then assigned to unsigned fw_level.
It will result in the number of cache leaves calculated incorrectly as a huge value which will then cause the following warning from __alloc_pages as the order would be great than MAX_ORDER because of incorrect and huge cache leaves value.
| WARNING: CPU: 0 PID: 1 at mm/page_alloc.c:5407 __alloc_pages+0x74/0x314 | Modules linked in: | CPU: 0 PID: 1 Comm: swapper/0 Not tainted 5.19.0-10393-g7c2a8d3ac4c0 #73 | pstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) | pc : __alloc_pages+0x74/0x314 | lr : alloc_pages+0xe8/0x318 | Call trace: | __alloc_pages+0x74/0x314 | alloc_pages+0xe8/0x318 | kmalloc_order_trace+0x68/0x1dc | __kmalloc+0x240/0x338 | detect_cache_attributes+0xe0/0x56c | update_siblings_masks+0x38/0x284 | store_cpu_topology+0x78/0x84 | smp_prepare_cpus+0x48/0x134 | kernel_init_freeable+0xc4/0x14c | kernel_init+0x2c/0x1b4 | ret_from_fork+0x10/0x20
Fix the same by changing fw_level to be signed integer and return the error from init_cache_level() early in case of error.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python-perfUpgrade kernel-livepatch-5.15.69-37.134Upgrade kernelUpgrade kernel-tools-develUpgrade perfUpgrade kernel-toolsUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-headersUpgrade kernel-tools-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade perf-debuginfoUpgrade bpftool-debuginfoUpgrade kernel-develUpgrade bpftoolUpgrade kernel-livepatch-5.10.144-127.601Upgrade python-perf-debuginfoUpgrade kernel-debuginfo | Jul 9, 2025 | Jun 18, 2025 |
| Debian | — | Upgrade linux | Jun 20, 2025 | Jun 20, 2025 |
| Dell Powerstore Dsa2025429 | — | Upgrade Dell PowerStoreOS to the latest version | Dec 3, 2025 | Dec 2, 2025 |
| Dell Powerstore Dsa2026039 | — | Upgrade Dell PowerStoreOS to the latest version | Jan 13, 2026 | Jan 6, 2026 |
| Huawei Euleros 2_0_sp10 | — | Upgrade python3-perfUpgrade kernel-toolsUpgrade kernel-tools-libsUpgrade kernel-abi-stablelistsUpgrade kernel | Sep 15, 2025 | Sep 9, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade kernel-toolsUpgrade python3-perfUpgrade kernelUpgrade kernel-abi-stablelistsUpgrade bpftoolUpgrade kernel-tools-libs | Oct 24, 2025 | Sep 9, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 18, 2025 |
| Ubuntu | — | Upgrade linux-bluefieldUpgrade linux-oracle-5.4Upgrade linux-realtimeUpgrade linuxUpgrade linux-riscv-5.15Upgrade linux-gkeUpgrade linux-raspi-5.4Upgrade linux-raspiUpgrade linux-awsUpgrade linux-aws-5.4Upgrade linux-lowlatency-hwe-5.15Upgrade linux-fipsUpgrade linux-ibm-5.4Upgrade linux-aws-5.15Upgrade linux-lowlatencyUpgrade linux-hwe-5.4Upgrade linux-azure-5.15Upgrade linux-gcpUpgrade linux-gcp-fipsUpgrade linux-gcp-5.15Upgrade linux-gcp-5.4Upgrade linux-hwe-5.15Upgrade linux-oracle-5.15Upgrade linux-azure-fipsUpgrade linux-azure-5.4Upgrade linux-kvmUpgrade linux-intel-iotgUpgrade linux-nvidiaUpgrade linux-aws-fipsUpgrade linux-intel-iotg-5.15Upgrade linux-azure-fde-5.15Upgrade linux-gkeopUpgrade linux-ibmUpgrade linux-oracleUpgrade linux-iotUpgrade linux-azure | Jun 26, 2025 | Jun 18, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Jun 18, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub