Impact
During execution of the kernel BPF helper __bpf_get_task_stack, the buffer passed as an argument is cleared only on successful returns. On failure paths the buffer remains uninitialized, which can be reused as a map key. This fault allows a local attacker to read deterministic garbage values from memory that may contain sensitive information or to inject faulty map entries, potentially leading to information leakage or a denial‑of‑service disposition for kernel‑level map handling.
Affected Systems
The vulnerability affects Linux kernel builds that expose the bpf_get_task_stack and bpf_get_task_stack_sleepable helpers without the recent fix that adds a memset on error. Systems running a kernel released before the commit that introduced the clearing logic are susceptible. No product version list is provided in the advisory, so any kernel without the patch may be impacted.
Risk and Exploitability
The EPSS rating is very low (< 1%) and the flaw is not on CISA’s KEV list, suggesting limited exploitation activity. Attack likely requires local action to load a crafted BPF program that triggers the helper on an error condition to read the garbage buffer. The absence of a publicly documented exploit and the inferred necessity of local BPF privileges keep the overall risk classed as low for most environments.
OpenCVE Enrichment