Junglewise Threat Intelligence

CVE-2022-49961: Linux Kernel BPF verifier out-of-bounds access via imprecise scalars

CVE-2022-49961 · Severity: high · CVSS 7.1 · Published 2025-06-18

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem could allow a local user with specific privileges to bypass security checks. The BPF verifier, which ensures that custom scripts are safe to run, fails to correctly track certain memory size constants. This flaw could allow a malicious script to perform out-of-bounds memory access, potentially leading to unauthorized data access or system instability.

Technical details

A vulnerability exists in the Linux kernel BPF verifier's handling of ARG_CONST_ALLOC_SIZE_OR_ZERO arguments. The verifier fails to call mark_chain_precision for these arguments, which means it may incorrectly treat two different register states as equivalent during state pruning (regsafe) if the registers are marked as imprecise. This allows a BPF program to bypass memory boundary checks, as the verifier might assume a memory region is larger than it actually is at runtime. An attacker with CAP_BPF privileges can exploit this to perform out-of-bounds reads or writes. The issue is resolved by ensuring precision markers are propagated using backtracking support when these arguments are encountered.

Affected products

  • Linux Linux Kernel 5.8 to 5.19.8

Timeline

  • 2022-08-23: patched: Initial patch authored
  • 2025-06-18: disclosed: CVE published

References

Related threats