Impact
A kernel bug allows the KCM string parser to execute a BPF program using bpf_prog_run_pin_on_cpu() without establishing an RCU read‑side critical section. The missing RCU lock permits CPU migration during BPF execution, and when the BPF program performs map operations it triggers the kernel warning WARN_ON_ONCE(!bpf_rcu_lock_held()). The warning indicates a breach of RCU invariants and could signal a condition that may lead to kernel instability if the race is exploited.
Affected Systems
All Linux kernel builds that have not yet incorporated the recent patch that adds an RCU read lock around BPF execution in the KCM string parser. The vendor data does not specify exact version ranges, so any kernel version prior to the release of the fix remains exposed.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in CISA KEV, indicating a low probability of automated exploitation. Attackers would need to supply a malicious BPF program or otherwise trigger the KCM strparser in a context where user‑supplied BPF code is executed, which typically requires elevated privileges or compromised user space. While the immediate impact is limited to a warning that may precede instability, the risk is elevated if an attacker can repeatedly trigger the condition. The CVSS score of 7.8 classifies this as a high‑severity vulnerability.
OpenCVE Enrichment
Debian DLA
Debian DSA