Impact
An attacker can exploit a flaw in the Linux kernel's BPF verifier that fails to confirm whether a symbol is a kernel function or another BPF program when CONFIG_FUNCTION_ERROR_INJECTION is disabled. This oversight permits a sleepable tracing program to attach to a BPF program whose name carries an __x64_ prefix. Once attached, the tracing program can invoke bpf_copy_from_user on a user pointer in an inappropriate execution context. This sequence can trigger a BUG in kernel/bpf/trampoline.c, resulting in a kernel panic. The impact is a denial of service that can crash the entire system, exposing all processes and data to interruption. The flaw is best classified as a type mismatch/incorrect verification weakness (CWE-704).
Affected Systems
Linux kernel binaries compiled with the default configuration that has CONFIG_FUNCTION_ERROR_INJECTION disabled are affected. No specific version range is listed in the advisory, implying that the vulnerability exists in recent kernel releases that contain the flawed verifier logic until the patch is applied. All organizations running a Linux distribution that relies on the upstream kernel or a derivative that preserves this code path must consider the update.
Risk and Exploitability
The vulnerability has an EPSS score of less than 1%, indicating a very low probability of exploitation. It is not listed in the CISA KEV catalog, suggesting no confirmed active exploitation. The reported attack likely requires an attacker to be able to load a custom BPF program, which could be accomplished locally or via elevated privileges in remote exploitation. In the absence of privileged access, the risk remains limited, but the potential for a system-wide crash remains significant if the flaw is exploited.
OpenCVE Enrichment