Impact
The Linux kernel’s BPF link subsystem contains a race condition in bpf_link_show_fdinfo and bpf_link_get_info_by_fd where a pointer to a BPF program (link->prog) is accessed without holding a lock. If a concurrent bpf_link_update frees the old program, the pointer becomes dangling, potentially allowing a use‑after‑free that can corrupt kernel memory or cause a crash. The vulnerability is explicitly a use‑after‑free flaw that could lead to kernel memory corruption, denial of service, or other unintended kernel execution behavior.
Affected Systems
All Linux kernel builds that include the BPF link subsystem but do not yet incorporate the RCU‑protected access introduced in commit 79347e42f are affected. In practice this means every mainstream kernel release prior to that commit, effectively covering the majority of production systems unless they have applied the patch or are running a newer kernel version.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity level, while the EPSS score of less than 1% shows a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. It is inferred that exploitation requires local or privileged access capable of creating or updating BPF links, after which the race can be triggered to cause kernel memory corruption or a crash.
OpenCVE Enrichment
Debian DLA
Debian DSA