Impact
A memory leak was discovered in the Linux kernel’s Berkeley Packet Filter (BPF) just-in-time (JIT) compiler. The bug occurs when JIT compilation of a subprogram fails after a successful first pass; the cleanup routine bpf_jit_free fails to release the jit_data->ctx.offset array. Repeated failures therefore cause the offsets array to remain allocated, incrementally consuming kernel memory. While the defect does not grant an attacker direct code execution, it can lead to resource exhaustion and potentially a denial‑of‑service condition if memory usage grows unchecked.
Affected Systems
All Linux kernel releases that contain the unpatched BPF JIT implementation are affected. The exact kernel version range is not specified in the advisory, so any system running a current kernel prior to the patch should be considered vulnerable.
Risk and Exploitability
The EPSS score is below 1 %, indicating a very low probability of exploitation. The CVSS score is not provided, but the vulnerability’s impact is limited to a gradual memory leak that could overwhelm the system over time. It is not listed in the CISA KEV catalog, and no public exploit is known. The likely attack vector is a local or remote user with permission to program BPF programs that trigger repeated JIT compilation failures. Given the low exploitation probability, monitoring and applying the patch remain the most prudent measures.
OpenCVE Enrichment
Debian DLA
Debian DSA