Impact
A bug in the Linux kernel's BPF tracing module causes the tracing_multi link to not be marked as ftrace managed. When a tracing_multi link is attached followed by an fentry link, the kernel fails to release the original link, leading to a resource leak that can exhaust kernel BPF link resources if repeated. This flaw corresponds to a resource management weakness (CWE‑401).
Affected Systems
All Linux distributions that ship a kernel containing the unpatched BPF tracing_multi implementation are affected. The bug exists in the core Linux kernel and applies to every system that can load BPF programs and has the capability to attach tracing links, regardless of distribution or specific kernel configuration.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity of the flaw. The EPSS score of less than 1 % signifies a low likelihood of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local and requires the ability to load BPF programs, such as a user with CAP_SYS_ADMIN privileges. An attacker could repetitively attach tracing_multi and fentry links, potentially exhausting BPF link resources and destabilizing the kernel. However, the CVE description does not explicitly state that this leads to a denial of service, so the impact is inferred but not definitively proven.
OpenCVE Enrichment