Impact
In the Linux kernel, the BPF verifier can incorrectly preserve a scalar identifier when a spilled register is reloaded using a sign‑extending narrow load (BPF_MEMSX). This flaw involves CWE‑125, CWE‑195, and CWE‑680 and results in the verifier believing that a subsequent zero‑extending load has replaced the value, while the actual register holds a different, sign‑extended value. The verifier may then refine conditions based on the wrong value and allow an out‑of‑bounds memory access to be compiled into the BPF program. The flaw can lead to memory corruption.
Affected Systems
All Linux kernel releases that contain the BPF verifier logic prior to the patch documented in this advisory are affected. The exact version range is not specified in the data, so any kernel build before the release that applied the fix must be evaluated. The issue touches the core BPF subsystem and therefore applies to all distributions that ship the upstream kernel without the upstream patch.
Risk and Exploitability
The CVSS score of 7.8 places the flaw in the high‑severity range, but the EPSS score of less than 1% indicates a low probability of active exploits at this time. The vulnerability is not listed in CISA's KEV catalog, suggesting no known active exploitation campaigns. An attacker would need to craft a BPF program that triggers the verifier’s sign‑extension logic, which typically requires privileged access to load custom eBPF programs. Consequently, the practical risk is limited to systems that allow untrusted users to load BPF code or that have an unpatched kernel.
OpenCVE Enrichment