eBPF has become a fundamental part of modern Linux, offering in-kernel programmability for networking, observability, and security tasks. Its rapid expansion, however, has enlarged the kernel’s attack surface—particularly in security-critical components such as the verifier—where frequent vulnerabilities have been reported. These flaws pose significant risks to kernel stability and security. This paper conducts a study of 249 eBPF-related Common Vulnerabilities and Exposures (CVE) records published between 2014 and April 2025, considering Common Weakness Enumeration (CWE) tags, Common Vulnerability Scoring System (CVSS) severity metrics, kernel-version mappings, timing, and more, enabling a comprehensive view of long-term trends. Our investigation focuses on the temporal evolution of eBPF-related vulnerabilities, how long they remain unpatched, where they occur within the eBPF subsystem, what coding flaws cause them, and how severe and impactful they are.
Analysis of the eBPF Vulnerabilities in the Linux Kernel / Rizza, R., Sisto, R., Valenza, F.. - 16295:(2026), pp. 221-236. (Risks and Security of Internet and Systems. CRiSIS 2025 Gatineau (CAN) 22-24 October 2025) [10.1007/978-3-032-20732-6_14].
Analysis of the eBPF Vulnerabilities in the Linux Kernel
Rosario Rizza;Riccardo Sisto;Fulvio Valenza
2026
Abstract
eBPF has become a fundamental part of modern Linux, offering in-kernel programmability for networking, observability, and security tasks. Its rapid expansion, however, has enlarged the kernel’s attack surface—particularly in security-critical components such as the verifier—where frequent vulnerabilities have been reported. These flaws pose significant risks to kernel stability and security. This paper conducts a study of 249 eBPF-related Common Vulnerabilities and Exposures (CVE) records published between 2014 and April 2025, considering Common Weakness Enumeration (CWE) tags, Common Vulnerability Scoring System (CVSS) severity metrics, kernel-version mappings, timing, and more, enabling a comprehensive view of long-term trends. Our investigation focuses on the temporal evolution of eBPF-related vulnerabilities, how long they remain unpatched, where they occur within the eBPF subsystem, what coding flaws cause them, and how severe and impactful they are.| File | Dimensione | Formato | |
|---|---|---|---|
|
Analysis_of_the_eBPF_Vulnerabilities_in_the_Linux_Kernel.pdf
embargo fino al 02/07/2027
Tipologia:
2. Post-print / Author's Accepted Manuscript
Licenza:
Pubblico - Tutti i diritti riservati
Dimensione
767 kB
Formato
Adobe PDF
|
767 kB | Adobe PDF | Visualizza/Apri Richiedi una copia |
|
978-3-032-20732-6_14.pdf
accesso riservato
Tipologia:
2a Post-print versione editoriale / Version of Record
Licenza:
Non Pubblico - Accesso privato/ristretto
Dimensione
2 MB
Formato
Adobe PDF
|
2 MB | Adobe PDF | Visualizza/Apri Richiedi una copia |
Pubblicazioni consigliate
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/11583/3003687
