Junglewise Threat Intelligence

CVE-2025-38528: Linux Kernel denial of service in BPF bprintf helpers

CVE-2025-38528 · Severity: high · CVSS 7.1 · Published 2025-08-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's BPF (Berkeley Packet Filter) subsystem, which is used for high-performance networking and system monitoring. An attacker could provide a specially crafted format string to certain kernel functions, causing the system to trigger internal warnings or potentially crash. This could lead to a denial of service or unauthorized access to sensitive kernel information, impacting system stability and security.

Technical details

A vulnerability exists in the Linux kernel's BPF subsystem within the bpf_bprintf_prepare function in kernel/bpf/helpers.c. The issue arises because the helper incorrectly skips over punctuation characters (such as a second '%') when processing the '%p' format specifier. This logic error allows malformed format strings like '%p%' to bypass initial validation, subsequently triggering a kernel warning in format_decode at runtime. A local attacker with permissions to load BPF programs can exploit this to cause a denial of service (kernel panic/warning) or potentially leak kernel memory information. The issue has been resolved by ensuring the validator does not skip punctuation, allowing subsequent iterations to correctly reject the invalid format.

Affected products

  • Linux Linux Kernel 5.13 to 6.16-rc5

Timeline

  • 2025-07-01: patched: Initial patch authored by Paul Chaignon
  • 2025-08-16: disclosed: CVE published

References

Related threats