Impact
A flaw in the Linux kernel BPF subsystem allows a device-bound BPF program to be registered or executed on a different network device when the internal developer match function mis‑evaluates net device pointers. The incorrect comparison lets a privileged caller (CAP_BPF + CAP_NET_ADMIN) create a BPF link with a mismatched target, causing the kernel to dereference a NULL or invalid pointer and trigger a general protection fault. The result is a kernel panic, effectively denying service for the affected host.
Affected Systems
Linux kernel builds prior to the patch that implements this fix are vulnerable. The issue applies to all architectures where the BPF MDP code is compiled, and is triggered when a user with capability to create BPF links attaches a program to an offload‑registered net device that is not its own device. Specific kernel versions are not enumerated in the advisory, but any kernel that includes the unpatched __bpf_offload_dev_match logic is affected.
Risk and Exploitability
The CVSS score is not listed in the input and EPSS data is not available, but the vulnerability requires local privileged execution. Once a CAP_BPF or CAP_NET_ADMIN user injects a test program, they can force a kernel crash and cause a denial of service on the host. The vulnerability is listed in no CISA KEV catalog and currently has no known public exploit, however the high impact and exploitability for privileged users warrant prompt remediation.
OpenCVE Enrichment