Impact
An internal bug in the Linux kernel’s BPF tracing subsystem incorrectly updates the flags used by the trampoline when a BPF tail‑call program is released. The verifier assigns the flag BPF_TRAMP_F_TAIL_CALL_CTX without accounting for existing flag bits, causing the trampoline to overwrite a target program’s NOP instruction with a JMP instruction or to restore the instruction with the wrong call encoding. This misbehavior can corrupt the target program’s code area and result in kernel instability or a crash.
Affected Systems
All stock Linux kernel releases that ship with BPF tracing support and do not include the patch that was committed in kernel revisions 48a0209d8da0d90a7b0a0db19d1ff88027b13781 and 61aaa8782bec59ecffd22e030f54ef9351bcabf9 are affected. The issue applies to every kernel version prior to the inclusion of these commits.
Risk and Exploitability
The CVSS score of 7.8 classifies the flaw as high severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation at the time of assessment, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local user with the ability to load custom BPF programs, so the attack vector is a privileged local adversary. Successful exploitation could lead to kernel memory corruption, crashes, or other instability, but does not provide a straightforward privilege escalation path.
OpenCVE Enrichment