Impact
The Linux kernel’s BPF interpreter does not understand the BPF_JMP|BPF_JA|BPF_X opcode used with the insn_array map. When a program containing this instruction is loaded, the interpreter triggers a BUG_ON in ___bpf_prog_run(), causing an oops and a kernel panic. The result is a local denial of service: the affected host becomes unusable until the system is rebooted or the kernel is fixed.
Affected Systems
All Linux kernel installations that have not applied the commit that disables interpreter fallback for the gotox instruction are vulnerable. This includes every distribution kernel version released before the patch commit 17da80d0c7b5. Services that compile or load BPF programs, such as networking devices, container runtimes, or system utilities, can trigger the fault if they use the insn_array map without the mitigation in place.
Risk and Exploitability
The EPSS score is under 1 % and the vulnerability is not in CISA’s KEV catalog, indicating a low current exploitation probability. No CVSS score has been assigned. The flaw requires local or privileged access to load a malicious BPF program, so the impact remains confined to the target machine. If such access is obtained, the attacker can achieve a DoS by forcing the kernel to crash, which disrupts all services on that host.
OpenCVE Enrichment