Impact
The vulnerability in the Linux kernel allows a null‑pointer dereference during a BPF program replacement in a cgroup context. When an empty program is replaced by a program that uses per‑CPU cgroup storage, the kernel fails to allocate the necessary storage for the new program, causing an uninitialized reference. If the replacement occurs, the kernel will panic, resulting in a denial‑of‑service condition for the entire system.
Affected Systems
All Linux kernel installations are potentially affected, as the issue resides in the core BPF and cgroup subsystems. The exact kernel versions are not enumerated, but any build that has not applied the patch is vulnerable.
Risk and Exploitability
The EPSS score indicates a very low likelihood of exploitation (<1 %). The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack likely requires a process with BPF loading permissions—typically root or a privileged user. Once executed, the kernel will crash, but achieving the replacement requires knowledge of the specific cgroup and BPF program context. The potential damage is high, yet the privileged nature of the required actions keeps the overall risk moderate to low in a hardened environment.
OpenCVE Enrichment
Debian DLA
Debian DSA