eBPF has become a fundamental part of modern Linux, offering in-kernel programmability for networking, observability, and security tasks. Its rapid expansion, however, has enlarged the kernel’s attack surface—particularly in security-critical components such as the verifier—where frequent vulnerabilities have been reported. These flaws pose significant risks to kernel stability and security. This paper conducts a study of 249 eBPF-related Common Vulnerabilities and Exposures (CVE) records published between 2014 and April 2025, considering Common Weakness Enumeration (CWE) tags, Common Vulnerability Scoring System (CVSS) severity metrics, kernel-version mappings, timing, and more, enabling a comprehensive view of long-term trends. Our investigation focuses on the temporal evolution of eBPF-related vulnerabilities, how long they remain unpatched, where they occur within the eBPF subsystem, what coding flaws cause them, and how severe and impactful they are.

Analysis of the eBPF Vulnerabilities in the Linux Kernel / Rizza, R., Sisto, R., Valenza, F.. - 16295:(2026), pp. 221-236. (Risks and Security of Internet and Systems. CRiSIS 2025 Gatineau (CAN) 22-24 October 2025) [10.1007/978-3-032-20732-6_14].

Analysis of the eBPF Vulnerabilities in the Linux Kernel

Rosario Rizza;Riccardo Sisto;Fulvio Valenza
2026

Abstract

eBPF has become a fundamental part of modern Linux, offering in-kernel programmability for networking, observability, and security tasks. Its rapid expansion, however, has enlarged the kernel’s attack surface—particularly in security-critical components such as the verifier—where frequent vulnerabilities have been reported. These flaws pose significant risks to kernel stability and security. This paper conducts a study of 249 eBPF-related Common Vulnerabilities and Exposures (CVE) records published between 2014 and April 2025, considering Common Weakness Enumeration (CWE) tags, Common Vulnerability Scoring System (CVSS) severity metrics, kernel-version mappings, timing, and more, enabling a comprehensive view of long-term trends. Our investigation focuses on the temporal evolution of eBPF-related vulnerabilities, how long they remain unpatched, where they occur within the eBPF subsystem, what coding flaws cause them, and how severe and impactful they are.
2026
978-3-032-20732-6
978-3-032-20731-9
File in questo prodotto:
File Dimensione Formato  
Analysis_of_the_eBPF_Vulnerabilities_in_the_Linux_Kernel.pdf

embargo fino al 02/07/2027

Tipologia: 2. Post-print / Author's Accepted Manuscript
Licenza: Pubblico - Tutti i diritti riservati
Dimensione 767 kB
Formato Adobe PDF
767 kB Adobe PDF   Visualizza/Apri   Richiedi una copia
978-3-032-20732-6_14.pdf

accesso riservato

Tipologia: 2a Post-print versione editoriale / Version of Record
Licenza: Non Pubblico - Accesso privato/ristretto
Dimensione 2 MB
Formato Adobe PDF
2 MB Adobe PDF   Visualizza/Apri   Richiedi una copia
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11583/3003687