Impact
The Linux kernel contains BPF queue and stack helper functions that rely on the verifier to initialize output buffers. When a lock acquisition fails, the helper returns -EBUSY without writing into the buffer, exposing uninitialized stack contents to BPF programs. An attacker could read this uninitialized memory, causing kernel or user‑space information leakage.
Affected Systems
All Linux kernel versions that expose the uninitialized queue and stack helpers and have not yet applied the patch are potentially affected; the specific versions are not enumerated in the available data.
Risk and Exploitability
The EPSS score of < 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no CVSS score is available. Based on the description, an attacker requires the capacity to load or influence eBPF programs, implying a local or higher privilege context. Although the probability of exploitation appears low, the potential for kernel memory exposure warrants prompt remediation.
OpenCVE Enrichment