VYPR
High severity7.8NVD Advisory· Published Apr 16, 2025· Updated Jul 30, 2026

CVE-2025-22087

CVE-2025-22087

Description

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix array bounds error with may_goto

may_goto uses an additional 8 bytes on the stack, which causes the interpreters[] array to go out of bounds when calculating index by stack_size.

1. If a BPF program is rewritten, re-evaluate the stack size. For non-JIT cases, reject loading directly.

2. For non-JIT cases, calculating interpreters[idx] may still cause out-of-bounds array access, and just warn about it.

3. For jit_requested cases, the execution of bpf_func also needs to be warned. So move the definition of function __bpf_prog_ret0_warn out of the macro definition CONFIG_BPF_JIT_ALWAYS_ON.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Linux/Kernel3 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.9,<6.12.23
    • (no CPE)
    • (no CPE)range: 6.9
  • osv-coords
    Range: >= 6.9.0, < 6.12.23

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.