Impact
A sleepable BPF program can acquire a spin lock that provides RCU protection for a kernel pointer. When the BPF verifier releases the lock via bpf_spin_unlock(), the RCU protection ends, but the verifier incorrectly keeps the pointer valid. This allows the kernel to free the object on another CPU before the pointer is dereferenced, producing a use‑after‑free of the task_struct in __bpf_get_task_stack(). The flaw can corrupt kernel memory if an attacker supplies a BPF program that triggers the scenario, potentially destabilizing the system. The weakness is an instance of CWE‑416 (Use After Free).
Affected Systems
All Linux kernel releases that shipped the BPF subsystem before the fix commit. Any kernel version where the BPF spin‑lock handling has not been patched is affected, including distribution‑specific kernels that have not applied the upstream update.
Risk and Exploitability
The CVSS score of 7.8 indicates a high impact if the flaw is exploited. The EPSS score of less than 1 % shows that real‑world exploitation is currently considered very unlikely, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the ability to inject or execute a BPF program that uses a spin‑locked RCU pointer, which typically demands local or kernel‑privileged access or the capability to load BPF code. The exact attack vector—local, privilege escalation, or remote—is not explicitly documented in the description and is therefore inferred to be local or requiring the ability to load BPF programs.
OpenCVE Enrichment