Impact
The BPF verifier in the Linux kernel incorrectly handles load‑acquire instructions that target pointers needing fault protection. The verifier does not rewrite such instructions to a probe‑memory form, so the JIT emits a plain load without a fault‑dispatch table entry. If the source pointer originates from an untrusted context, dereferencing it can trigger a kernel panic instead of a graceful fault. This behavior effectively turns certain BPF programs into a denial‑of‑service vector by crashing the kernel when they access untrusted memory such as a NULL or non‑live mm_struct field.
Affected Systems
All Linux kernel releases before the commit that introduced this fix are impacted. The vulnerability affects any kernel that processes BPF programs containing load_acquire instructions on pointers that the verifier would normally protect, such as pointers derived from task_struct->mm or other untrusted reference points. Distribution‑specific version ranges are not listed in the CVE data, so users should verify that their running kernel incorporates the patch commit.
Risk and Exploitability
The CVSS score is not specified, and the EPSS score is listed as less than 1 %, indicating a very low probability of exploitation in the wild. The vulnerability is not currently listed in CISA’s KEV catalog. An attacker would need to inject a malicious BPF program that exercises load_acquire on an untrusted pointer, which requires kernel‑level privileges or the ability to execute captive BPF code. If such a program is loaded, the result is a kernel panic that disables the host until reboot or patch is applied.
OpenCVE Enrichment