Impact
A Linux kernel BPF helper combination allows a LWT_SEG6LOCAL program to invalidate its cached SRH pointer by calling bpf_lwt_seg6_adjust_srh() and subsequently invoke bpf_skb_pull_data(). The helper may reallocate skb->head, leaving the per‑CPU SRH pointer dangling. When the program ends, post‑program SRH validation writes through the stale pointer, resulting in memory corruption inside the kernel. This can compromise the integrity of kernel memory and potentially lead to local privilege escalation or denial of service if the attacker can load such a program.
Affected Systems
All Linux kernels that provide support for LWT_SEG6LOCAL BPF programs are impacted. The vulnerability is specific to the kernel’s BPF verifier logic; version information is not provided, so any kernel before the patch that allows LWT_SEG6LOCAL programs and exposes the helper combination is considered vulnerable. Systems running updated kernels where the verifier rejects the helper are no longer affected.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not in the CISA KEV catalog, which suggests limited publicly reported exploitation. However, the nature of the flaw—kernel memory corruption—implies a high potential severity if an attacker can load a LWT_SEG6LOCAL program. The attack requires local privileged execution to load the program, so the vector is internal. In environments where BPF program loading is possible by non‑root users, the risk increases. Absent an official CVSS score, the risk is judged as significant because the vulnerability can lead to compromise of kernel memory.
OpenCVE Enrichment