Impact
A logic error in the Linux kernel’s BPF subsystem caused the offset guard for the spin‑lock resource to be mistakenly checked against the wrong variable, BPF_SPIN_LOCK, instead of res_spin_lock_off. Based on the description, it is inferred that this flaw can trigger a memory validation bypass, leading to kernel memory corruption if exploited. Such corruption may allow an attacker to overwrite critical kernel data structures, potentially escalating privileges or crashing the system, thereby compromising confidentiality, integrity, and availability.
Affected Systems
All Linux kernel releases that contain the BPF subsystem and do not include the patch commit 04e19012efaec2bfd8c3b37fd8a6c3f1fe731ffc are affected. This includes any vendor distribution of the Linux kernel without the applied fix, regardless of distribution variant. The bug resides in the core kernel code, so any machine running an unpatched kernel is vulnerable.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is execution of a malicious eBPF program from user space that triggers the faulty offset check, which generally requires local or remote code execution with sufficient privileges. As no CVSS score is provided, the exact severity is not quantified, but the potential for kernel memory corruption suggests a high impact if the flaw is exploited.
OpenCVE Enrichment