Impact
The BPF verifier in the Linux kernel erroneously treats MEM_RCU and PTR_UNTRUSTED iterator stack slots as equal. This miscomparison allows the verifier to prune an unsafe path incorrectly, enabling carefully crafted eBPF programs to execute kernel operations that are normally prohibited. The consequence is kernel‑mode code execution, effectively granting an attacker elevated privileges within the kernel.
Affected Systems
The bug resides in the Linux kernel BPF subsystem and affects all kernel releases that incorporate the unpatched verifier logic. Since the advisory does not list specific releases, all current and prior Linux kernel versions lacking the patch are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8. EPSS score of less than 1% suggests a low probability of widespread exploitation. The flaw is not listed in the CISA KEV catalog. Attackers would need the capability to load eBPF programs, a function that typically requires CAP_SYS_ADMIN or root access. Based on the description, it is inferred that such privilege is necessary before the vulnerability can be exercised. Once a program is accepted, the malformed verifier bypass can lead to arbitrary kernel code execution.
OpenCVE Enrichment