Impact
The kernel’s BPF module expects callbacks to match a specific ABI. During task work scheduling, the callback was invoked through a three‑argument function pointer, a mismatch that triggers the kernel’s Control‑Flow Integrity (kCFI) checks. The result is an assertion failure and a kernel panic, effectively shutting down the system. This failure is a classic kernel memory corruption, mapped to CWE‑760.
Affected Systems
All Linux kernel releases preceding the commit that introduced the fix are affected. The vulnerability resides in the generic BPF subsystem and the task work execution path. Vendors that ship unmodified upstream kernels, such as the mainline Linux kernel maintained by the Linux Foundation, are included. No specific vendor product strings or version ranges are listed in the CNA data, so the impact covers every system with an unpatched kernel.
Risk and Exploitability
EPSS is below 1% and the vulnerability is not listed in CISA KEV, indicating a low probability of widespread exploitation. Based on the description, it is inferred that an attacker would need to load a BPF program with appropriate privileges, typically root or a capability such as CAP_SYS_ADMIN. Once the callback is invoked, the kernel crashes, resulting in a denial‑of‑service. The lack of a known public exploit and the local nature of the required privilege mean the risk is moderate but still significant for any systems that allow unrestricted BPF code execution.
OpenCVE Enrichment