Impact
A recent kernel fix addresses an issue where BPF programs that attach to fexit, fmod_ret, fsession or struct_ops could receive only the lower 8 bytes of a 16‑byte return value. The original trampoline preserved only the low half of the result, while the upper half was discarded, causing the attached BPF program and the real caller to see a corrupted value. This truncation can lead to incorrect program behaviour and potential data integrity problems within kernel space.
Affected Systems
The vulnerability impacts all Linux distributions running a kernel version that includes the buggy return‑reading trampoline behaviour. There is no specific product or version list supplied, but it applies to any kernel where BPF attach types fexit, fmod_ret, fsession (and the _multi variants) or struct_ops were employed before the patch.
Risk and Exploitability
The EPSS score is reported as < 1%, indicating a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalogue. The CVSS score is not provided, so severity inference is limited. Based on the description, the attack vector is likely a malicious BPF program that makes a >8byte return and is attached via a return‑reading type; the program would then observe a truncated value, potentially leading to subtle kernel inconsistencies. No privileged escalation is explicitly described, but the data corruption could be leveraged in a complex attack chain if the impacted value influences critical logic.
OpenCVE Enrichment