Impact
The Linux kernel BPF subsystem allows program-type callbacks to validate writes to BTF pointers before the default access path rejects non‑read operations. This bypasses the intended read‑only policy for untrusted pointers created by helper functions such as bpf_rdonly_cast. The result is that a BPF program can write to kernel memory through an untrusted BTF pointer, which violates the kernel’s access control. Based on the description, it is inferred that this flaw could allow an attacker to corrupt kernel data and potentially elevate privileges.
Affected Systems
Linux kernel installations that have not incorporated the commit referenced in the advisory are affected. The advisory lists Linux as the vendor and the Linux kernel as the product. No specific version range is supplied, so the flaw applies to any kernel prior to the commit that adds the rejection of non‑read accesses for untrusted BTF pointers.
Risk and Exploitability
The CVSS score of 7.8 indicates a medium‑to‑high level of severity. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, and no public exploits are known. Based on the description, it is inferred that the likely attack vector would involve loading a BPF program that uses untrusted BTF pointers, which typically requires local or elevated privileges. The overall risk is moderate, but the potential impact warrants prompt remediation if the system has not been patched.
OpenCVE Enrichment