Executive brief
A vulnerability was identified in the Linux kernel's BPF (Berkeley Packet Filter) subsystem, which is used for high-performance networking and system monitoring. An attacker could provide a specially crafted format string to certain kernel functions, causing the system to trigger internal warnings or potentially crash. This could lead to a denial of service or unauthorized access to sensitive kernel information, impacting system stability and security.
Technical details
A vulnerability exists in the Linux kernel's BPF subsystem within the bpf_bprintf_prepare function in kernel/bpf/helpers.c. The issue arises because the helper incorrectly skips over punctuation characters (such as a second '%') when processing the '%p' format specifier. This logic error allows malformed format strings like '%p%' to bypass initial validation, subsequently triggering a kernel warning in format_decode at runtime. A local attacker with permissions to load BPF programs can exploit this to cause a denial of service (kernel panic/warning) or potentially leak kernel memory information. The issue has been resolved by ensuring the validator does not skip punctuation, allowing subsequent iterations to correctly reject the invalid format.
Affected products
- Linux Linux Kernel 5.13 to 6.16-rc5
Timeline
- 2025-07-01: patched: Initial patch authored by Paul Chaignon
- 2025-08-16: disclosed: CVE published
References
- https://git.kernel.org/stable/c/1c5f5fd47bbda17cb885fe6f03730702cd53d3f8
- https://git.kernel.org/stable/c/61d5fa45ed13e42af14c7e959baba9908b8ee6d4
- https://git.kernel.org/stable/c/6952aeace93f8c9ea01849efecac24dd3152c9c9
- https://git.kernel.org/stable/c/97303e541e12f1fea97834ec64b98991e8775f39
- https://git.kernel.org/stable/c/e7be679124bae8cf4fa6e40d7e1661baddfb3289
- https://git.kernel.org/stable/c/f8242745871f81a3ac37f9f51853d12854fd0b58
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html