Impact
The Linux kernel vulnerability arises from an out‑of‑bounds read of the sk_protocol field in bpf_sock_destroy(). The field resides in struct sock, but the code reads it from a struct sock_common that does not contain it. When a socket in TIME_WAIT or NEW_SYN_RECV state is passed to the BPF iterator, the kernel attempts to read past the end of the object, triggering a KASAN error and often resulting in a crash. This bug falls under the weakness of improper input validation (CWE‑20) and can lead to denial of service by crashing the kernel or an application that relies on the socket state.
Affected Systems
The flaw is present in all versions of the Linux kernel that have not incorporated the patch commit referenced in the advisory. The affected product is the Linux kernel, distributed by the Linux Foundation, for all architectures that implement BPF socket iterators.
Risk and Exploitability
The advisory does not list a KEV or an EPSS score, indicating that no widespread exploitation has been reported and the likelihood of accidental exploitation is low. Nevertheless, the vulnerability can be triggered by loading a BPF program that accesses sockets through the iterator interface, which is typically a local or privileged action. If an attacker can inject such a BPF program, they could cause a kernel crash and disrupt availability. The exploit requires kernel knowledge and the ability to load BPF code, so while the path is clear, the practical risk remains moderate until a patch is applied.
OpenCVE Enrichment