Junglewise Threat Intelligence

CVE-2025-40169: Linux Kernel BPF verifier incorrect validation of ALU operation offsets

CVE-2025-40169 · Severity: high · CVSS 7.8 · Published 2025-11-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's BPF (Berkeley Packet Filter) subsystem, which is used for high-performance networking and system monitoring. A flaw in how the system validates certain mathematical operations could allow a local attacker to bypass security checks. If exploited, this could lead to unauthorized access to sensitive data, system instability, or full control over the affected machine.

Technical details

The vulnerability exists in the `check_alu_op()` function within `kernel/bpf/verifier.c`. The verifier intended to restrict the 'offset' field of ALU instructions to values of 0 or 1 (specifically for BPF_MOD and BPF_DIV). However, because the offset is a signed 16-bit integer, the original check `insn->off > 1` failed to reject negative values. A local attacker with the ability to load BPF programs could exploit this logic error to pass malformed instructions that bypass verifier safety guarantees. This could lead to arbitrary kernel memory access or privilege escalation. The issue has been patched by explicitly checking that the offset is either 0 or 1.

Affected products

  • Linux Linux Kernel 6.6 to 6.6.112, 6.12 to 6.12.53, 6.17 to 6.17.3

Timeline

  • 2025-11-12: advisory
  • 2025-10-15: patched

References

Related threats