CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's BPF (Berkeley Packet Filter) subsystem, where a failure in memory allocation can lead to a leak of sensitive data stored in `insn_aux_data`. This issue can potentially expose sensitive information, making it critical for organizations using Linux systems with BPF functionality to prioritize remediation. System administrators and security teams should assess their environments for this vulnerability to prevent potential data leaks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix insn_aux_data leak on verifier err_free_env path When bpf_check() allocates env->insn_aux_data successfully but later fails to allocate env->succ, it jumps directly to err_free_env. The existing vfree(env->insn_aux_data) sits before the err_free_env label, so that direct jump bypasses it and leaks insn_aux_data. Move vfree(env->insn_aux_data) into err_free_env so all early and late exit paths release it consistently.