Impact
A BPF program attached to a cgroup getsockopt hook can reduce the optlen field after the kernel handler has executed. Because the kernel accepts negative optlen values, they are propagated to the TCP getsockopt path and ultimately cast to size_t for copy_to_sockptr(). This may trigger a hardened usercopy warning for bytes greater than INT_MAX and can potentially result in memory corruption or a failure of the hardened copy logic. The weakness involves improper input validation and length handling in kernel code.
Affected Systems
All Linux kernel builds are impacted because the vulnerability resides in the core BPF and getsockopt logic. Versions prior to the application of the patch that rejects negative optlen values are susceptible; specific version identifiers are not provided in the report.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation at present. The attack requires delivery of a BPF program that runs in a cgroup getsockopt hook, which typically requires local or privileged access to load the program. Because the flaw involves kernel memory handling, successful exploitation could lead to privilege escalation or denial of service, but no publicly available exploits are known.
OpenCVE Enrichment
Debian DLA
Debian DSA