Impact
The vulnerability lies in the Linux kernel BPF subsystem’s bpf_get_stackid routine. In the affected code, preemption remains enabled while the routine accesses a stack trace buffer, creating a race condition that can corrupt kernel memory. The advisory notes that a commit has been applied to disable preemption for this path, but it does not detail the exact outcome if the race occurs. The flaw potentially leads to unstable kernel behavior or crashes when the BPF subsystem is used for performance monitoring.
Affected Systems
All Linux kernel installations that have not yet applied the commit disabling preemption in bpf_get_stackid are affected. This includes out‑of‑date kernels across major distributions that rely on the BPF subsystem for tracing or performance analysis.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity if the race can be exercised. The EPSS score of < 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that a local user with the ability to load or execute BPF programs that invoke bpf_get_stackid could trigger the race, potentially leading to kernel buffer corruption or a crash.
OpenCVE Enrichment
Debian DLA
Debian DSA