Impact
During a recent kernel modification, a race condition was identified in the BPF subsystem’s net‑namespace link update routine. The code performs checks on the existing program pointer and program type without holding the netns_bpf_mutex, permitting two threads to update the same link concurrently. One thread can replace the program pointer, free it, and allow the other thread to continue using the stale reference, producing a use‑after‑free. In a kernel context, such memory corruption can lead to silent data corruption, kernel crashes, or an attacker gaining elevated privileges through crafted BPF programs.
Affected Systems
The flaw exists in the Linux kernel source tree and will affect any distribution that ships a kernel containing the unpatched implementation. The issue is present across all vendors that ship the default Linux Kernel and does not have a targeted version string, so any kernel built from the pre‑commit source remains vulnerable until the patch is applied.
Risk and Exploitability
The EPSS score is below 1 %, indicating a low probability of current exploitation in the wild. The vulnerability is not in the CISA KEV catalog, which aligns with the historical detection of this bug. The use‑after‑free race requires the ability to submit BPF link update requests; an attacker would need local or privileged access to install malicious BPF functions or to trigger the race. While the attack surface is limited, the impact of a successful exploit could be a kernel crash or arbitrary code execution, making the flaw high‑impact if an attacker can meet the prerequisites.
OpenCVE Enrichment
Debian DLA
Debian DSA