Impact
The vulnerability occurs in the Linux kernel's BPF subsystem, where an unsettled link is incorrectly handled by the link iterator. If an attacker creates a BPF link that is inserted into the IDR before it is settled, a subsequent call to bpf_link_put can dereference freed memory. This use‑after‑free can trigger a kernel panic. The weakness is a classic use‑after‑free flaw (CWE‑416).
Affected Systems
This bug affects all Linux kernel builds that do not incorporate the patch; the CPE identifier indicates the Linux kernel in general. No specific version range is listed, so any current kernel may be vulnerable unless the commit that introduced the fix is present. Users should verify their kernel version against the referenced commits.
Risk and Exploitability
The CVSS score is not provided and EPSS is unavailable, so quantitative risk data is missing. The issue is not listed in the CISA KEV catalog, indicating that no confirmed exploitation has been recorded. Based on the description, it is inferred that a local attacker who can create BPF link objects can trigger the flaw, making the attack vector likely local. The bug can cause a kernel panic (Denial of Service).
OpenCVE Enrichment