Impact
The vulnerability resides in the Linux kernel’s XDP (eXpress Data Path) handling. An XDP link created with a normal BPF program can later be updated to an offloaded or device‑bound program via BPF_LINK_UPDATE, bypassing the validation checks that normally run in dev_xdp_attach(). The missing checks allow the kernel to install an XDP program on the software path that is not intended for such execution, which can lead to incorrect packet processing, instability, or a crash. This flaw stems from improper enforcement of program type restrictions and offload requirements, making the kernel behave inconsistently with its documented design.
Affected Systems
Any system running a Linux kernel version prior to the patch that implements the fix in commit 03022dd874070768a7099f18b1944c633641315f is affected. The failure is in the core networking stack and applies to all builds that enable XDP (CONFIG_XDP) regardless of distribution or architecture. No explicit vendor or minor version is supplied, so any exposed Linux kernel is potentially impacted until the commit is deployed.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the EPSS score of less than 1% reflects a low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog, the wild at the time of analysis. A local user with the ability to create and update BPF XDP links can exploit the flaw; remote exploitation would require mechanisms to gain such access. If successfully leveraged, the flaw could result in a denial‑of‑service condition through kernel instability or unfiltered packet handling, but it does not provide a direct privilege escalation path.
OpenCVE Enrichment