Impact
The Linux kernel contains a flaw in the handling of BPF Type Format (BTF) structure walks. The kernel relaxes the struct‑size check for accesses through a trailing flexible array, which is acceptable for normal BTF type walking but mistakenly allows the same relaxation for MEM_ALLOC objects whose BTF type size is static. When a loader walks a MEM_ALLOC object, the kernel rejects the access only after applying the flexible‑array relaxation, permitting the code to read past the bounds of the allocated kernel buffer. This results in an out‑of‑bounds read that can leak kernel memory contents. The vulnerability is a classic buffer overread and does not provide a direct path to code execution.
Affected Systems
All Linux kernel distributions that include kernel versions prior to the fix are affected. The vendor is Linux and the product is the Linux kernel. No specific version range is provided in the advisory, so any kernel version older than the patched release should be considered vulnerable.
Risk and Exploitability
The EPSS score is below 1%, indicating a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 7.8 denotes high severity. Based on the description, it is inferred that an attacker must be able to load a malicious eBPF program to trigger the out‑of‑bounds read, implying a local or privileged attack context. No evidence of remote exploitation is present in the advisory.
OpenCVE Enrichment