Executive brief
A vulnerability in the Linux kernel's BPF subsystem could allow a local user to cause a system crash or instability. The issue occurs when specific monitoring or networking programs (BPF) attempt to send signals while the system is in a state where it cannot safely pause. This can lead to a kernel panic or 'deadlock,' resulting in a complete service outage for the affected machine.
Technical details
A vulnerability exists in the Linux kernel's BPF implementation where the bpf_send_signal() kfunc can be invoked in non-preemptible contexts. Because this function can sleep, calling it in such contexts violates kernel execution constraints, potentially leading to deadlocks or kernel panics. The root cause was an insufficient check using irqs_disabled(), which did not account for all non-preemptible states; this has been corrected by using the !preemptible() check to ensure signals are sent asynchronously when necessary. A local attacker with the ability to load and execute BPF programs could trigger this condition to cause a Denial of Service (DoS). Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 5.4.33 to 5.4.291, 5.6.1 to 5.10.235, 5.11 to 5.15.179, 5.16 to 6.1.129, 6.2 to 6.6.76, 6.7 to 6.12.13, 6.13 to 6.13.2
Timeline
- 2025-01-15: patched: Initial fix committed to mainline kernel
- 2025-02-27: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/092fc76b7ab4163e008f9cde596a58dad2108260
- https://git.kernel.org/stable/c/78b97783496b454435639937db3303e900a24d3f
- https://git.kernel.org/stable/c/87c544108b612512b254c8f79aa5c0a8546e2cc4
- https://git.kernel.org/stable/c/be42a09fe898635b0093c0c8dac1bfabe225c240
- https://git.kernel.org/stable/c/ce51eab2070e295d298f42a2f1db269cd1b56d55
- https://git.kernel.org/stable/c/e306eaaa3d78b462db5f5b11e0171f9d2b6ca3f4
- https://git.kernel.org/stable/c/eeef8e65041a031bd8a747a392c14b76a123a12c