Linux Kernel BPF Verifier Backtracking Bug Vulnerability

Vulnerability

A vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) verifier has been addressed. The issue arose because the verifier did not properly handle invalid kfunc (kernel function) calls during instruction backtracking. This oversight could lead to a backtracking bug warning, indicating a verifier backtracking issue. The vulnerability has been resolved by making the backtracking process more conservative.

Impact

Exploitation of this vulnerability could cause a backtracking bug in the BPF verifier, potentially leading to incorrect verification of BPF programs.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.