Impact
A flaw in the Linux kernel’s BPF type‑facing system causes duplicate field identifiers in nested structures to be misidentified as unique during recursive searches. This oversight allows a crafted BPF type format to trigger an invariant warning before the kernel verifies user capabilities when creating a map, potentially bypassing security checks or leading to a kernel warning that could impact stability.
Affected Systems
All Linux kernel versions that include the underscored bug in the bpf subsystem are affected. No specific releases are listed in the data; the issue existed prior to the patch that modified btf_find_field to propagate the seen mask across recursion.
Risk and Exploitability
The EPSS score indicates a very low exploitation probability, and the vulnerability is not in CISA’s KEV catalog. However, an attacker could supply a malicious BTF definition through a user process, exploiting the lack of uniqueness tracking to either gain unauthorized map creation privileges or provoke a kernel warning path that may be used for denial of service. The attack would require the ability to load custom BPF programs and absence of mitigations that reject invalid BTF data.
OpenCVE Enrichment
Debian DLA
Debian DSA