Impact
The vulnerability arises from per‑CPU BPF map elements being stored with a padded size that is rounded up to the nearest multiple of eight bytes. When a lookup occurs via the UAPI, the kernel copies only the unpadded value into a temporary buffer but the buffer itself is not zeroed. The unused padding area may contain stale heap data, which is then returned to user space. An attacker able to perform a BPF lookup on a per‑CPU map can therefore read unintended memory contents, exposing sensitive data that was never meant for user space.
Affected Systems
All Linux kernel releases that contain the per-CPU BPF map implementation are affected. The vulnerability is present in the generic Linux kernel.
Risk and Exploitability
The EPSS score is under 1 %, indicating a low probability of exploitation at present. The CVE is not listed in the CISA KEV catalog. The vulnerability is local: it requires a process that can load BPF programs and has access to per‑CPU maps, which is typically a privileged or specially allowed user. Exploitation would result in data disclosure rather than code execution or denial of service. The lack of a publicly known exploit and the low EPSS score suggest the immediate risk is low, but the information disclosure could aid in credential or privilege escalation if combined with other weaknesses.
OpenCVE Enrichment
Debian DLA
Debian DSA