Impact
The Linux kernel contains a flaw that allows the __pcpu_freelist_push function to enter an infinite loop when only one CPU is possible and an NMI re‑enters the function while that CPU’s freelist lock is held. The fallback loop that searches for another CPU runs without finding any candidates on a 1‑CPU system, so a lock is never acquired and the loop never terminates. The result is a system hang or an unresponsive state, effectively denying service to userspace processes relying on BPF events.
Affected Systems
Affected systems are all Linux kernel builds that do not yet contain the upstream patch referenced in the commit logs. The CPE indicates that every linux_kernel variant is potentially vulnerable, with no specific version constraints provided. Administrators should assume that any on‑premises kernel lacking the patch is at risk.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low exploitation probability in the wild. The bug is local and requires kernel execution or privileged code to trigger the BPF path during an NMI, allowing an attacker to generate an NMI that re‑enters __pcpu_freelist_push. Although a CVSS score has not been provided, the impact of a system hang is significant. Existing mitigations rely on applying the kernel patch; no workaround has been documented.
OpenCVE Enrichment