Back

HIGH

openrisc: fix arbitrary kernel memory access via or1k_atomic syscall

Published Sep 11, 2026

Description

sys_or1k_atomic() (syscall 244 in the "or1k" ABI) takes two user pointers, v1 and v2, and swaps the words they point to in hand-written assembly.

l.lwz r29,0(r4) l.lwz r27,0(r5) l.sw 0(r4),r27 l.sw 0(r5),r29

The pointers are not checked with access_ok(). The four memory accesses also have no exception table entries.

A caller passes a kernel address as either pointer, and the syscall reads from and writes to it directly.

This gives an unprivileged process a kernel read/write primitive. It overwrites kernel data such as the sys_call_table, gaining code execution in kernel context.

Check both pointers before entering the critical section. Add fixups for the four memory accesses so faults on valid but unmapped user addresses return -EFAULT.

[shorne@gmail.com: fix comment style]

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Sep 11, 2026
Updated Sep 14, 2026
Reserved Sep 11, 2026

CISA Vulnrichment

No data

NVD

Status Received
Modified Sep 14, 2026

Red Hat

Severity Moderate
Public date Sep 11, 2026
Bugzilla 2532099

ENISA EUVD

Assigner Linux
Published Sep 11, 2026
Updated Sep 14, 2026

GitHub

No data