Impact
When a Linux kernel architecture such as LoongArch, ARM64, or RISC‑V implements bpf_jit_inlines_helper_call, the verifier skips rewriting the helper call offset in the BPF interpreter path. If JIT is disabled or fails at runtime, the interpreter executes the raw helper enum ID, which jumps to an invalid address. The execution of this invalid address triggers an instruction alignment fault or directly causes a kernel panic. The vulnerability is a consequence of improper initialization of program metadata that allows a control‑flow error. An attacker who can load a BPF program on the affected kernel can force the system to crash, resulting in a denial of service.
Affected Systems
All Linux kernel builds that contain the bpf_jit_inlines_helper_call feature for architectures such as LoongArch, ARM64, and RISC‑V are affected. This covers every kernel release prior to the patch that enforces prog->jit_required=1. No distribution‑specific version limits are listed, so any system running an unpatched kernel with the inlining capability is vulnerable.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low current exploitation probability. Exploitation requires the ability to inject or load a BPF program, which typically necessitates elevated privileges or a separate software flaw that permits BPF code submission. Once the program is present, an attacker can trigger the interpreter fallback by disabling JIT (net.core.bpf_jit_enable = 0) or by causing a compiler failure such as an out‑of‑memory condition. Remote exploitation would need an additional vector that allows BPF program loading; otherwise the impact remains limited to privileged local attacks.
OpenCVE Enrichment