Impact
The bug allows a BPF program attached to the Linux kernel's cgroup UNIX getname hooks to call _bpf_setsockopt() or _bpf_getsockopt() without holding the socket lock that these helpers normally require. When executed in the hooks, the helpers trigger a sock_owned_by_me() warning, which can lead to a kernel fault and a system crash. The weakness is a race‐condition style flaw in the kernel's locking logic, and it can be categorized as a concurrent execution with shared resource issue.
Affected Systems
All Linux kernel builds that implement the cgroup UNIX getname hooks are potentially affected, as the CPE indicates a generic kernel version. No specific version constraints are listed in the CVE data, so any kernel revision that includes the getname hooks and has not been patched by the upstream commit is vulnerable.
Risk and Exploitability
The EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to load a BPF program attached to the CGROUP_UNIX_GETPEERNAME or CGROUP_UNIX_GETSOCKNAME hooks, which normally requires local user privileges or the ability to inject code with CAP_BPF. The vulnerability can result in denial of service through a kernel crash, but its exploitability is limited to environments where the attacker can control BPF program loading.
OpenCVE Enrichment
Debian DLA
Debian DSA