Impact
The vulnerability occurs in the Linux kernel’s BPF subsystem, specifically in the bpf_trampoline_update path. When an update fails before unregistering an old trampoline image, the ftrace engine continues to reference the freed image, leading to a use‑after‑free. An attacker who can influence the BPF update can potentially execute code using the dereferenced memory, resulting in arbitrary code execution or privilege escalation.
Affected Systems
All Linux kernel implementations that include the bpf_trampoline_multi_attach_free path are potentially vulnerable. No specific kernel versions are listed, so you should verify whether your running kernel contains the unpatched implementation.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is below 1%, indicating a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need the ability to load or modify BPF programs, typically requiring normal user privileges but may be constrained by system policies. Based on the description, the likely attack vector involves submitting a BPF program that triggers the bpf_trampoline_update failure, leading to the use‑after‑free. The flaw can be mitigated by applying the kernel patch that ensures the old image is freed only when it differs from the current image.
OpenCVE Enrichment