Impact
The defect originates in the Linux kernel’s BPF subsystem. An atomic read‑modify‑write instruction records the pointer type only when the destination is marked as a special arena pointer. A second execution path can reach the same instruction with an ordinary pointer that bypasses the earlier type check. After verification the instruction is rewritten to perform an atomic operation regardless of the actual pointer type. This mismatch allows a crafted BPF program to cause the kernel to treat an incompatible pointer as a valid atomic target, leading to unintended memory writes or corruption. Such memory corruption can be leveraged by an attacker to gain elevated privileges or crash the system.
Affected Systems
All Linux kernel binaries are affected. The CVE does not specify a vulnerable version range; any system running a kernel build that lacks the referenced patch commits is considered vulnerable.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity. The EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via loading a BPF program that targets a userland process. Attackers would need privileged capabilities such as CAP_NET_ADMIN or CAP_SYS_ADMIN to load BPF programs; once loaded, the exploit runs in kernel context, giving the attacker the potential for kernel‑level privilege escalation or denial of service.
OpenCVE Enrichment