Executive brief
A vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem can cause a system crash when Control Flow Integrity (CFI) is enabled. The issue occurs during cryptographic operations when the system attempts to release memory using an incorrectly typed function. This results in a kernel 'oops' or crash, potentially leading to a denial of service for the affected system.
Technical details
A vulnerability exists in the Linux kernel's BPF crypto component where an incorrect function pointer type is used for a destructor kfunc. When CONFIG_CFI is enabled, the kernel enforces strict type matching for indirect function calls. The function bpf_crypto_ctx_release was being called in a context expecting a different signature, specifically during bpf_obj_free_fields. This mismatch triggers a CFI failure and a subsequent kernel panic (Oops). The fix involves introducing a stub function, bpf_crypto_ctx_release_dtor, with the correct 'void *' argument type to satisfy both the BPF verifier and CFI requirements.
Affected products
- Linux Linux Kernel 6.1, 6.6, 6.7, 6.8
Timeline
- 2026-01-10: other: Patch authored
- 2026-05-08: disclosed: CVE published