« Volver al listado

CVE-2026-46250

Estado: AnalizadaAlta (7.3)—

In the Linux kernel, the following vulnerability has been resolved:

MIPS: Work around LLVM bug when gp is used as global register variable

On MIPS, __current_thread_info is defined as global register variable locating in $gp, and is simply assigned with new address during kernel relocation.

This however is broken with LLVM, which always restores $gp if it finds $gp is clobbered in any form, including when intentionally through a global register variable. This is against GCC's documentation[1], which requires a callee-saved register used as global register variable not to be restored if it's clobbered.

Leer descripción completaMostrar menos

As a result, $gp will continue to point to the unrelocated kernel after the epilog of relocate_kernel(), leading to an early crash in init_idle,

This bug has been reported to LLVM[2] and affects version from (at least) 18 to 21. Let's work around this by using inline assembly to assign $gp before a fix is widely available.

Detalles técnicos trazas, registros y código del informe original
[    0.000000] CPU 0 Unable to handle kernel paging request at virtual address 0000000000000000, epc == ffffffff81afada8, ra == ffffffff81afad90
[    0.000000] Oops[#1]:
[    0.000000] CPU: 0 UID: 0 PID: 0 Comm: swapper Tainted: G        W           6.19.0-rc5-00262-gd3eeb99bbc99-dirty #188 VOLUNTARY
[    0.000000] Tainted: [W]=WARN
[    0.000000] Hardware name: loongson,loongson64v-4core-virtio
[    0.000000] $ 0   : 0000000000000000 0000000000000000 0000000000000001 0000000000000000
[    0.000000] $ 4   : ffffffff80b80ec0 ffffffff80b53d48 0000000000000000 00000000000f4240
[    0.000000] $ 8   : 0000000000000100 ffffffff81d82f80 ffffffff81d82f80 0000000000000001
[    0.000000] $12   : 0000000000000000 ffffffff81776f58 00000000000005da 0000000000000002
[    0.000000] $16   : ffffffff80b80e40 0000000000000000 ffffffff80b81614 9800000005dfbe80
[    0.000000] $20   : 00000000540000e0 ffffffff81980000 0000000000000000 ffffffff80f81c80
[    0.000000] $24   : 0000000000000a26 ffffffff8114fb90
[    0.000000] $28   : ffffffff80b50000 ffffffff80b53d40 0000000000000000 ffffffff81afad90
[    0.000000] Hi    : 0000000000000000
[    0.000000] Lo    : 0000000000000000
[    0.000000] epc   : ffffffff81afada8 init_idle+0x130/0x270
[    0.000000] ra    : ffffffff81afad90 init_idle+0x118/0x270
[    0.000000] Status: 540000e2	KX SX UX KERNEL EXL
[    0.000000] Cause : 00000008 (ExcCode 02)
[    0.000000] BadVA : 0000000000000000
[    0.000000] PrId  : 00006305 (ICT Loongson-3)
[    0.000000] Process swapper (pid: 0, threadinfo=(____ptrval____), task=(____ptrval____), tls=0000000000000000)
[    0.000000] Stack : 9800000005dfbf00 ffffffff8178e950 0000000000000000 0000000000000000
[    0.000000]         0000000000000000 ffffffff81970000 000000000000003f ffffffff810a6528
[    0.000000]         0000000000000001 9800000005dfbe80 9800000005dfbf00 ffffffff81980000
[    0.000000]         ffffffff810a6450 ffffffff81afb6c0 0000000000000000 ffffffff810a2258
[    0.000000]         ffffffff81d82ec8 ffffffff8198d010 ffffffff81b67e80 ffffffff8197dd98
[    0.000000]         ffffffff81d81c80 ffffffff81930000 0000000000000040 0000000000000000
[    0.000000]         0000000000000000 0000000000000000 0000000000000000 0000000000000000
[    0.000000]         0000000000000000 000000000000009e ffffffff9fc01000 0000000000000000
[    0.000000]         0000000000000000 0000000000000000 0000000000000000 0000000000000000
[    0.000000]         0000000000000000 ffffffff81ae86dc ffffffff81b3c741 0000000000000002
[    0.000000]         ...
[    0.000000] Call Trace:
[    0.000000] [<ffffffff81afada8>] init_idle+0x130/0x270
[    0.000000] [<ffffffff81afb6c0>] sched_init+0x5c8/0x6c0
[    0.000000] [<ffffffff81ae86dc>] start_kernel+0x27c/0x7a8

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local en kernel MIPS que causa pánico y negación de servicio durante el arranque (crash en init_idle) por fallo en reubicación de kernel con LLVM, sin interacción de usuario.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-46250",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
              "lessThan": "05bff9b0ae095b2420cfebb4a96759a09334bec6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
              "lessThan": "1fe3b402b1e97a1718df3be0a1d3eee20133e735",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
              "lessThan": "4dc65b40fb80c2020efbf139b9a38d30f9a37b92",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
              "lessThan": "c0155dee51b9f5f48aaf5c71cae005eb0e36521f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
              "lessThan": "e3a6498a63394218561065a9a7a597a204f52f6a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
              "lessThan": "561834f6d6f52b8a1791331e94b2aac753491d2a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
              "lessThan": "9bc3b0ae5203aba650297fdf3e1e774125e423f2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "279b991b24d2439fbe9d2f093988b9c8aed2603d",
              "lessThan": "30bfc2d6a1132a89a5f1c3b96c59cf3e4d076ea3",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/mips/kernel/relocate.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.252",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.202",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.165",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.128",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.75",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.14",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "6.19.4",
              "versionType": "semver",
              "lessThanOrEqual": "6.19.*"
            },
            {
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/mips/kernel/relocate.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-06-03T18:16:25.400",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/05bff9b0ae095b2420cfebb4a96759a09334bec6",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1fe3b402b1e97a1718df3be0a1d3eee20133e735",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/30bfc2d6a1132a89a5f1c3b96c59cf3e4d076ea3",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4dc65b40fb80c2020efbf139b9a38d30f9a37b92",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/561834f6d6f52b8a1791331e94b2aac753491d2a",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9bc3b0ae5203aba650297fdf3e1e774125e423f2",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c0155dee51b9f5f48aaf5c71cae005eb0e36521f",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e3a6498a63394218561065a9a7a597a204f52f6a",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nMIPS: Work around LLVM bug when gp is used as global register variable\n\nOn MIPS, __current_thread_info is defined as global register variable\nlocating in $gp, and is simply assigned with new address during kernel\nrelocation.\n\nThis however is broken with LLVM, which always restores $gp if it finds\n$gp is clobbered in any form, including when intentionally through a\nglobal register variable. This is against GCC's documentation[1], which\nrequires a callee-saved register used as global register variable not to\nbe restored if it's clobbered.\n\nAs a result, $gp will continue to point to the unrelocated kernel after\nthe epilog of relocate_kernel(), leading to an early crash in init_idle,\n\n[    0.000000] CPU 0 Unable to handle kernel paging request at virtual address 0000000000000000, epc == ffffffff81afada8, ra == ffffffff81afad90\n[    0.000000] Oops[#1]:\n[    0.000000] CPU: 0 UID: 0 PID: 0 Comm: swapper Tainted: G        W           6.19.0-rc5-00262-gd3eeb99bbc99-dirty #188 VOLUNTARY\n[    0.000000] Tainted: [W]=WARN\n[    0.000000] Hardware name: loongson,loongson64v-4core-virtio\n[    0.000000] $ 0   : 0000000000000000 0000000000000000 0000000000000001 0000000000000000\n[    0.000000] $ 4   : ffffffff80b80ec0 ffffffff80b53d48 0000000000000000 00000000000f4240\n[    0.000000] $ 8   : 0000000000000100 ffffffff81d82f80 ffffffff81d82f80 0000000000000001\n[    0.000000] $12   : 0000000000000000 ffffffff81776f58 00000000000005da 0000000000000002\n[    0.000000] $16   : ffffffff80b80e40 0000000000000000 ffffffff80b81614 9800000005dfbe80\n[    0.000000] $20   : 00000000540000e0 ffffffff81980000 0000000000000000 ffffffff80f81c80\n[    0.000000] $24   : 0000000000000a26 ffffffff8114fb90\n[    0.000000] $28   : ffffffff80b50000 ffffffff80b53d40 0000000000000000 ffffffff81afad90\n[    0.000000] Hi    : 0000000000000000\n[    0.000000] Lo    : 0000000000000000\n[    0.000000] epc   : ffffffff81afada8 init_idle+0x130/0x270\n[    0.000000] ra    : ffffffff81afad90 init_idle+0x118/0x270\n[    0.000000] Status: 540000e2\tKX SX UX KERNEL EXL\n[    0.000000] Cause : 00000008 (ExcCode 02)\n[    0.000000] BadVA : 0000000000000000\n[    0.000000] PrId  : 00006305 (ICT Loongson-3)\n[    0.000000] Process swapper (pid: 0, threadinfo=(____ptrval____), task=(____ptrval____), tls=0000000000000000)\n[    0.000000] Stack : 9800000005dfbf00 ffffffff8178e950 0000000000000000 0000000000000000\n[    0.000000]         0000000000000000 ffffffff81970000 000000000000003f ffffffff810a6528\n[    0.000000]         0000000000000001 9800000005dfbe80 9800000005dfbf00 ffffffff81980000\n[    0.000000]         ffffffff810a6450 ffffffff81afb6c0 0000000000000000 ffffffff810a2258\n[    0.000000]         ffffffff81d82ec8 ffffffff8198d010 ffffffff81b67e80 ffffffff8197dd98\n[    0.000000]         ffffffff81d81c80 ffffffff81930000 0000000000000040 0000000000000000\n[    0.000000]         0000000000000000 0000000000000000 0000000000000000 0000000000000000\n[    0.000000]         0000000000000000 000000000000009e ffffffff9fc01000 0000000000000000\n[    0.000000]         0000000000000000 0000000000000000 0000000000000000 0000000000000000\n[    0.000000]         0000000000000000 ffffffff81ae86dc ffffffff81b3c741 0000000000000002\n[    0.000000]         ...\n[    0.000000] Call Trace:\n[    0.000000] [<ffffffff81afada8>] init_idle+0x130/0x270\n[    0.000000] [<ffffffff81afb6c0>] sched_init+0x5c8/0x6c0\n[    0.000000] [<ffffffff81ae86dc>] start_kernel+0x27c/0x7a8\n\nThis bug has been reported to LLVM[2] and affects version from (at\nleast) 18 to 21. Let's work around this by using inline assembly to\nassign $gp before a fix is widely available."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nMIPS: Solución alternativa para el error de LLVM cuando gp se usa como variable de registro global\n\nEn MIPS, __current_thread_info se define como una variable de registro global ubicada en $gp, y simplemente se le asigna una nueva dirección durante la reubicación del kernel.\n\nEsto, sin embargo, se rompe con LLVM, que siempre restaura $gp si encuentra que $gp ha sido sobrescrito de alguna forma, incluso cuando es intencionalmente a través de una variable de registro global. Esto va en contra de la documentación de GCC[1], que requiere que un registro guardado por la función llamada, utilizado como variable de registro global, no sea restaurado si ha sido sobrescrito.\n\nComo resultado, $gp continuará apuntando al kernel no reubicado después del epílogo de relocate_kernel(), lo que lleva a un fallo temprano en init_idle,\n\n[    0.000000] CPU 0 No se puede manejar la solicitud de paginación del kernel en la dirección virtual 0000000000000000, epc == ffffffff81afada8, ra == ffffffff81afad90\n[    0.000000] Oops[#1]:\n[    0.000000] CPU: 0 UID: 0 PID: 0 Comm: swapper Tainted: G        W           6.19.0-rc5-00262-gd3eeb99bbc99-dirty #188 VOLUNTARY\n[    0.000000] Tainted: [W]=WARN\n[    0.000000] Nombre del hardware: loongson,loongson64v-4core-virtio\n[    0.000000] $ 0   : 0000000000000000 0000000000000000 0000000000000001 0000000000000000\n[    0.000000] $ 4   : ffffffff80b80ec0 ffffffff80b53d48 0000000000000000 00000000000f4240\n[    0.000000] $ 8   : 0000000000000100 ffffffff81d82f80 ffffffff81d82f80 0000000000000001\n[    0.000000] $12   : 0000000000000000 ffffffff81776f58 00000000000005da 0000000000000002\n[    0.000000] $16   : ffffffff80b80e40 0000000000000000 ffffffff80b81614 9800000005dfbe80\n[    0.000000] $20   : 00000000540000e0 ffffffff81980000 0000000000000000 ffffffff80f81c80\n[    0.000000] $24   : 0000000000000a26 ffffffff8114fb90\n[    0.000000] $28   : ffffffff80b50000 ffffffff80b53d40 0000000000000000 ffffffff81afad90\n[    0.000000] Hi    : 0000000000000000\n[    0.000000] Lo    : 0000000000000000\n[    0.000000] epc   : ffffffff81afada8 init_idle+0x130/0x270\n[    0.000000] ra    : ffffffff81afad90 init_idle+0x118/0x270\n[    0.000000] Status: 540000e2\tKX SX UX KERNEL EXL\n[    0.000000] Cause : 00000008 (ExcCode 02)\n[    0.000000] BadVA : 0000000000000000\n[    0.000000] PrId  : 00006305 (ICT Loongson-3)\n[    0.000000] Proceso swapper (pid: 0, threadinfo=(____ptrval____), task=(____ptrval____), tls=0000000000000000)\n[    0.000000] Pila : 9800000005dfbf00 ffffffff8178e950 0000000000000000 0000000000000000\n[    0.000000]         0000000000000000 ffffffff81970000 000000000000003f ffffffff810a6528\n[    0.000000]         0000000000000001 9800000005dfbe80 9800000005dfbf00 ffffffff81980000\n[    0.000000]         ffffffff810a6450 ffffffff81afb6c0 0000000000000000 ffffffff810a2258\n[    0.000000]         ffffffff81d82ec8 ffffffff8198d010 ffffffff81b67e80 ffffffff8197dd98\n[    0.000000]         ffffffff81d81c80 ffffffff81930000 0000000000000040 0000000000000000\n[    0.000000]         0000000000000000 0000000000000000 0000000000000000 0000000000000000\n[    0.000000]         0000000000000000 000000000000009e ffffffff9fc01000 0000000000000000\n[    0.000000]         0000000000000000 0000000000000000 0000000000000000 0000000000000000\n[    0.000000]         0000000000000000 ffffffff81ae86dc ffffffff81b3c741 0000000000000002\n[    0.000000]         ...\n[    0.000000] Rastro de llamadas:\n[    0.000000] [<ffffffff81afada8>] init_idle+0x130/0x270\n[    0.000000] [<ffffffff81afb6c0>] sched_init+0x5c8/0x6c0\n[    0.000000] [<ffffffff81ae86dc>] start_kernel+0x27c/0x7a8\n\nEste error ha sido reportado a LLVM[2] y afecta a las versiones desde (al menos) la 18 hasta la 21. Evitemos esto usando ensamblador en línea para asignar $gp antes de que una solución esté ampliamente disponible."
    }
  ],
  "lastModified": "2026-07-22T20:10:00.127",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A3B5D01-BD96-4232-A26F-686A4EAC3A0C",
              "versionEndExcluding": "5.10.252",
              "versionStartIncluding": "4.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4002FC2B-1456-4666-B240-0EBF590C4671",
              "versionEndExcluding": "5.15.202",
              "versionStartIncluding": "5.11"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "797C7F46-D0BE-4FB8-A502-C5EF8E6B6654",
              "versionEndExcluding": "6.1.165",
              "versionStartIncluding": "5.16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "851E9353-6C09-4CC9-877E-E09DB164A3C2",
              "versionEndExcluding": "6.6.128",
              "versionStartIncluding": "6.2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BCE16369-98ED-41CF-8995-DFDC10B288D2",
              "versionEndExcluding": "6.12.75",
              "versionStartIncluding": "6.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF463CB7-1F58-4607-B847-77ED23E4B9B7",
              "versionEndExcluding": "6.18.14",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "672A3E79-EC03-479D-8503-361DFBDC8092",
              "versionEndExcluding": "6.19.4",
              "versionStartIncluding": "6.19"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}