CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel, specifically in the RISC-V architecture, where uninitialized stack variables can lead to register corruption during error handling in certain functions. This flaw may allow for the leakage of sensitive kernel stack data and compromise the integrity of the target task's register state. Organizations using Linux on RISC-V systems should prioritize addressing this vulnerability to mitigate potential security risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: riscv: Fix register corruption from uninitialized cregs on error compat_riscv_gpr_set() calls cregs_to_regs() unconditionally, even when user_regset_copyin() fails. Since cregs is an uninitialized stack variable, a copyin failure causes uninitialized stack data to be written into the target task's pt_regs, corrupting its register state and potentially leaking kernel stack contents. compat_restore_sigcontext() has the same issue: it calls cregs_to_regs() even when __copy_from_user() fails, leading to the same corruption of the signal-returning task's register state on error. Only call cregs_to_regs() when the user copy succeeds.