Junglewise Threat Intelligence

CVE-2025-40079: Linux Kernel RISC-V BPF JIT improper sign extension

CVE-2025-40079 · Severity: high · CVSS 7.8 · Published 2025-10-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's RISC-V architecture support could allow a local attacker to cause a system crash (kernel panic). The issue stems from how the system handles specific internal programming instructions (BPF) related to network traffic management. If exploited, this could lead to a complete loss of system availability, potentially disrupting business operations and services running on affected RISC-V hardware.

Technical details

The vulnerability is located in arch/riscv/net/bpf_jit_comp64.c within the Linux kernel. It arises because the BPF trampoline for RISC-V incorrectly handles return values for 'struct ops' programs, treating pointers as 32-bit values and sign-extending them to 64-bit in the epilogue. This violates the RISC-V ABI requirements for these specific operation types. An attacker with local access could trigger this condition (e.g., via the ns_bpf_qdisc selftest or similar BPF-based network configurations), resulting in an invalid memory access and a kernel panic. Patches have been released in various stable branches including 6.12.53 and 6.17.3.

Affected products

  • Linux Linux Kernel 6.6 to 6.17.3, 6.18

Timeline

  • 2025-09-08: disclosed: Initial patch submission by Hengqi Chen
  • 2025-10-15: patched: Commits merged into stable branches
  • 2025-10-28: advisory: CVE-2025-40079 published

References

Related threats