Impact
The vulnerability is a type‑confusion flaw in the Linux kernel BPF virtual machine. During a load‑acquire instruction that writes back into the source register, the verifier incorrectly overwrites the register’s type, bypassing a pointer‑type check. As a result a malicious BPF program can load kernel data through an unvalidated pointer, enabling arbitrary reads of kernel memory and potentially privilege escalation.
Affected Systems
It affects all kernel releases that include the buggy commit 422a416041172af1ac610736d5f556d22b31b115 and its successors. The flaw resides in the eBPF subsystem used by tools such as bpftool, networking packet filters, and other kernel components that load eBPF programs. Users running older kernel releases should verify whether the fix has been incorporated and plan an upgrade if it is absent.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1 % signals a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the likely attack vector is the injection or execution of crafted BPF bytecode through a privileged interface such as bpftool or a kernel socket; once the verifier accepts the code, the type‑confusion allows an unrestricted read of kernel memory.
OpenCVE Enrichment