Impact
The Linux kernel’s BPF arena free routine, bpf_arena_free_pages(), accepts scalar arena addresses that are masked to the low 32 bits before reconstructing a full user address from the arena base. When the scalar value is below the low‑32‑bits of the arena base, the reconstructed address falls below user_vm_start. The existing upper‑end clipping then converts this to an out‑of‑range free‑tree offset. A subsequent allocation can reuse that offset, returning a kernel pointer that is below the arena mapping, which can corrupt kernel memory and potentially allow an attacker to execute code with root privileges.
Affected Systems
All Linux kernel releases before the patch referenced in the CVE description are affected. The vulnerability is present in the general Linux kernel, affecting any system that loads BPF programs and uses arena allocation.This includes both upstream kernel versions and the kernel shipped by most Linux distributions until the patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score of <1% suggests that exploitation of this bug in the wild is currently unlikely. The issue is not listed in CISA’s KEV catalog. Exploitation would require a privileged local attacker capable of loading a crafted BPF program that triggers the free mechanism; it is not a remotely exploitable flaw.
OpenCVE Enrichment
Debian DLA
Debian DSA