Privilege Escalation Vulnerability in OpenRISC Architecture by Linux Kernel
CVE-2026-80560
What is CVE-2026-80560?
A vulnerability in the Linux kernel's OpenRISC architecture allows an unprivileged task to exploit signal handling mechanisms. By manipulating the signal frame, an attacker can clear specific control bits in the hardware supervision register (SR), leading to unauthorized read and write access to arbitrary physical memory. This local privilege escalation occurs as the data Memory Management Unit (MMU) is disabled, exposing various critical registers to user control. The kernel has been updated to ensure that only non-privileged arithmetic flag bits are restored during signal return, thus effectively preventing this type of attack.
Affected Version(s)
Linux ac689eb7f9d4e270d1365853b82eece669387e2c
Linux ac689eb7f9d4e270d1365853b82eece669387e2c
Linux ac689eb7f9d4e270d1365853b82eece669387e2c