Impact
The Linux kernel contains a vulnerability in the BPF trampoline handling for 128‑bit arguments. The function that prepares stack frames for BPF calls assumes a 128‑bit scalar needs only one register, causing the register save area to be under‑allocated. When a 128‑bit argument is passed, the save_args routine writes beyond the allocated stack region, corrupting adjacent stack slots. This stack‑based buffer overflow can potentially lead to arbitrary code execution or a kernel panic, compromising system confidentiality, integrity, or availability. The weakness stems from improper calculation of stack space and is an instance of a stack‑based buffer overflow (CWE‑121).
Affected Systems
The flaw resides in the Linux kernel’s BPF subsystem. The affected products are Linux kernel builds that include the BPF component, but specific version ranges are not provided—the fix applies to any kernel containing the uncorrected stack size logic. Administrators should review the kernel release notes for versions containing the relevant commits.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1% implies that exploitation is unlikely at present. The vulnerability is not yet listed in the CISA KEV catalog. Attackers would need the ability to load or influence BPF programs, typically requiring privileged or local access, to exploit the stack corruption. Given the low probability and the need for local system access, the risk is moderate but warrants remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA