Impact
The Linux kernel implementation of bpf_cpumask_populate() allows the helper to write to memory addresses belonging to read‑only cpumask structures. The helper expects a struct cpumask * destination, which the verifier can supply with a borrowed pointer returned by a const kfunc such as scx_bpf_get_online_cpumask(). Because the destination is not typed as a BPF‑specific cpumask, the helper performs bitmap_copy() to a writable address that the kernel is not supposed to modify, leading to arbitrary kernel memory writes and corruption of kernel data structures. This violates the ownership rules for mutable cpumask manipulation and can undermine system integrity. The weakness is related to improper resource handling (CWE‑687) and could enable an attacker to modify privileged data and potentially elevate privileges. The impact is confined to kernel memory; user data is not directly exposed.
Affected Systems
The flaw exists in all Linux kernel releases that include the bpf_cpumask_populate() helper and the associated kfuncs. The vendor is Linux, product Linux kernel. No specific version range is listed in the advisories, so any kernel containing the vulnerable helper should be treated as affected. Users should check the running kernel version against vendor release notes to determine whether the fix is present and plan an upgrade accordingly.
Risk and Exploitability
The CVSS score is 7.1, indicating high severity. The EPSS score is reported as less than 1%, suggesting the likelihood of exploitation is currently low; however, kernel exploitation is a serious threat regardless of current prevalence. The vulnerability is not listed in the CISA KEV catalog, meaning no active exploitation has been documented. The likely attack vector requires an attacker to load a malicious BPF program that calls bpf_cpumask_populate() with a borrowed read‑only cpumask pointer. This requires a local or privileged context that can execute BPF code, but does not depend on additional conditions such as network access or service exposure. Consequently, the risk is moderate to high for systems that allow untrusted BPF program execution or provide local root privileges.
OpenCVE Enrichment