Impact
A race condition exists in the Linux kernel’s BPF verifier when it lazily parses the vmlinux BTF data. The pointer to the parsed structure is released through a plain store while the contents are still being initialized. On weakly ordered architectures, a concurrent caller that bypasses the lock can see an uninitialized pointer and later read incomplete or stale data, potentially exposing kernel memory to unintended observers. This race is an example of improper initialization weakness, which could allow malicious code to exploit kernel data structures before they are safely constructed.
Affected Systems
All current mainline releases of the Linux kernel that include the BPF BTF loader and use the bpf_get_btf_vmlinux function are vulnerable until the smp_store_release/smp_load_acquire changes are applied. The advisory does not specify individual version ranges, so any kernel version from the last stable commit before the patch is considered affected.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, yet the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a presently low probability of exploitation. The race would be triggered by simultaneous BPF program loading on a weakly ordered CPU, and the advisory does not provide evidence of a direct attack path. Consequently, while the impact is potentially significant, the exploitation likelihood remains uncertain without further evidence.
OpenCVE Enrichment
Debian DLA
Debian DSA