Impact
The kernel’s BPF cgroup attach routine can leave a program with dangling storage references after a failed replacement operation, enabling an attacker to trigger invalid memory accesses when the program executes. This kernel memory corruption can lead to a crash or escalation of privileges if the attacker can control the replacement flow.
Affected Systems
All Linux kernel implementations are affected, as the vulnerability is present in the core kernel code handling BPF cgroup attachments. No specific kernel version ranges are listed, so any unpatched kernel is potentially vulnerable.
Risk and Exploitability
The EPSS score falls below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of widespread exploitation today. However, the flaw requires the ability to load or replace BPF programs in cgroup contexts, which typically requires elevated privileges or kernel module access. The lack of a public exploit does not eliminate risk, as privileged users could inadvertently trigger a kernel crash or exploit the memory corruption to elevate privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA