PT-2025-25995 · Linux+3 · Linux Kernel+3

Published

2022-07-29

·

Updated

2025-06-18

·

CVE-2022-50069

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.19.0-rc7
Description A potential bad pointer dereference issue exists in the bpf sys bpf() helper function, which allows an eBPF program to load another eBPF program from within the kernel. The issue arises when the argument union bpf attr pointer is a kernel address instead of a userspace address. This can lead to problems when an eBPF syscall program tries to call bpf sys bpf() to load a program but provides a bad insns pointer. The code is always happy to dereference the bad pointer, triggering a page fault and an oops.
Recommendations For Linux kernel versions prior to 5.19.0-rc7, update to a newer version to mitigate the risk. As a temporary workaround, consider restricting the use of the bpf sys bpf() helper function until a patch is available. Avoid using the insns pointer in the bpf attr union to minimize the risk of exploitation.

Exploit

Fix

RCE

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03129
CESA-2022_7683
CVE-2022-50069
RHSA-2022:7683
RHSA-2022_7683
RHSA-2023:2458
RHSA-2023_2458

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat