Analysis of the eBPF Vulnerabilities in the Linux Kernel
At a glance
- الاستشهادات
- 0
- المراجع
- 0
- Comments
- 0
Abstract
eBPF has become a fundamental part of modern Linux, offering in-kernel programmability for networking, observability, and security tasks. Its rapid expansion, however, has enlarged the kernel’s attack surface—particularly in security-critical components such as the verifier—where frequent vulnerabilities have been reported. These flaws pose significant risks to kernel stability and security. This paper conducts a study of 249 eBPF-related Common Vulnerabilities and Exposures (CVE) records published between 2014 and April 2025, considering Common Weakness Enumeration (CWE) tags, Common Vulnerability Scoring System (CVSS) severity metrics, kernel-version mappings, timing, and more, enabling a comprehensive view of long-term trends. Our investigation focuses on the temporal evolution of eBPF-related vulnerabilities, how long they remain unpatched, where they occur within the eBPF subsystem, what coding flaws cause them, and how severe and impactful they are.
Publication details
- DOI
- 10.5281/zenodo.17711508
- OpenAlex
- W7106810072
- Document type
- preprint
- Language
- EN
- Source
- Zenodo (CERN European Organization for Nuclear Research)
- Last metadata update
Comments
تسجيل الدخول للانضمام إلى النقاش.