Impact
In the Linux kernel, a use-after-free condition exists in the bpf_find_vma() function. When the function accesses a foreign task’s mm_struct without holding a reference, a concurrent task exit can free the mm_struct between the lockless read and the subsequent mmap_read_trylock call. This can lead to memory corruption or a kernel crash if the freed mm_struct is later accessed.
Affected Systems
All Linux kernel releases prior to the patch that implements commit 2b2a903bee56d312539046d9defa8023eec94760. The vulnerability is located in the bpf subsystem and affects any kernel that allows BPF programs to query foreign task VMAs.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, signifying a low probability of exploitation. The likely attack vector is a local kernel attacker who can load a malicious BPF program and target a foreign task that is concurrently exiting – this is an inference based on the described race condition and the need for precise timing between the BPF call and task exit.
OpenCVE Enrichment
Debian DLA
Debian DSA