Impact
A bug in the Linux kernel arises when a sleepable LSM BPF program is freed in a softirq context. The kernel calls a function that performs a sleeping operation from a non‑sleepable context, triggering the built‑in BUG macro and resulting in a kernel panic or Oops. The failure is an implicit assertion violation caused by calling a sleeping function from an invalid context, leading to a loss of system stability and potential denial of service. No direct exploitation of privileges is disclosed, but the crash can be leveraged to destabilize services running on the affected host.
Affected Systems
All Linux kernel deployments that (or that may) use sleepable LSM BPF programs are impacted. The vulnerability was found in the core kernel code, affecting all mainstream Linux distributions that ship the standard kernel source tree. The CPE indicates the Linux kernel itself, and the vendor list lists Linux in general.
Risk and Exploitability
The EPSS score is below 1 %, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, and no CVSS score is provided, so the inherent severity is based on the kernel panic effect. The likely attack vector is the normal use of BPF programs with an LSM hook attached; an attacker with the ability to load or modify BPF bytecode could deliberately trigger the bug by enabling a sleepable LSM observer. Classic kernel debugging or monitoring mechanisms would reveal the BUG trigger in kernel logs.
OpenCVE Enrichment
Debian DLA
Debian DSA