{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T11:05:18Z","timestamp":1784027118883,"version":"3.55.0"},"publisher-location":"Cham","reference-count":21,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032207319","type":"print"},{"value":"9783032207326","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-20732-6_14","type":"book-chapter","created":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T10:28:14Z","timestamp":1784024894000},"page":"221-236","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Analysis of\u00a0the\u00a0eBPF Vulnerabilities in\u00a0the\u00a0Linux Kernel"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-0498-8304","authenticated-orcid":false,"given":"Rosario","family":"Rizza","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3142-2383","authenticated-orcid":false,"given":"Riccardo","family":"Sisto","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8471-3029","authenticated-orcid":false,"given":"Fulvio","family":"Valenza","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,2]]},"reference":[{"key":"14_CR1","doi-asserted-by":"publisher","unstructured":"Bhandari, G., Naseer, A., Moonen, L.: Cvefixes: automated collection of vulnerabilities and their fixes from open-source software. In: Proceedings of the 17th International Conference on Predictive Models and Data Analytics in Software Engineering, pp. 30\u201339. PROMISE 2021. Association for Computing Machinery, New York (2021). https:\/\/doi.org\/10.1145\/3475960.3475985, https:\/\/doi.org\/10.1145\/3475960.3475985","DOI":"10.1145\/3475960.3475985"},{"key":"14_CR2","unstructured":"Corporation, M.: Common weakness enumeration (cwe). https:\/\/cwe.mitre.org (2025), https:\/\/cwe.mitre.org"},{"key":"14_CR3","unstructured":"Edge, J.: Bpf and security (2023). https:\/\/lwn.net\/Articles\/946389\/. Accessed 17 Sept 2025"},{"key":"14_CR4","doi-asserted-by":"publisher","unstructured":"Fan, J., Li, Y., Wang, S., Nguyen, T.N.: A c\/c++ code vulnerability dataset with code changes and cve summaries. In: Proceedings of the 17th International Conference on Mining Software Repositories, pp. 508\u2013512. MSR \u201920, Association for Computing Machinery, New York (2020).https:\/\/doi.org\/10.1145\/3379597.3387501, https:\/\/doi.org\/10.1145\/3379597.3387501","DOI":"10.1145\/3379597.3387501"},{"key":"14_CR5","unstructured":"Forum of Incident Response and Security Teams (FIRST): The epss model. https:\/\/www.first.org\/epss\/model (2025). Accessed 17 Sept 2025"},{"key":"14_CR6","doi-asserted-by":"publisher","unstructured":"Gershuni, E., Amit, N., Gurfinkel, A., Narodytska, N., Navas, J.A., Rinetzky, N., Ryzhyk, L., Sagiv, M.: Simple and precise static analysis of untrusted linux kernel extensions. In: Proceedings of the 40th ACM SIGPLAN Conference on Programming Language Design and Implementation, pp. 1069\u20131084. PLDI 2019. Association for Computing Machinery, New York (2019).https:\/\/doi.org\/10.1145\/3314221.3314590, https:\/\/doi.org\/10.1145\/3314221.3314590","DOI":"10.1145\/3314221.3314590"},{"key":"14_CR7","doi-asserted-by":"publisher","unstructured":"Hung, H.W., Amiri\u00a0Sani, A.: Brf: Fuzzing the ebpf runtime. Proc. ACM Softw. Eng. 1(FSE) (Jul 2024). https:\/\/doi.org\/10.1145\/3643778","DOI":"10.1145\/3643778"},{"key":"14_CR8","doi-asserted-by":"publisher","unstructured":"Jia, J., Sahu, R., Oswald, A., Williams, D., Le, M.V., Xu, T.: Kernel extension verification is untenable. In: Proceedings of the 19th Workshop on Hot Topics in Operating Systems, pp. 150\u2013157. HOTOS \u201923, Association for Computing Machinery, New York (2023). https:\/\/doi.org\/10.1145\/3593856.3595892, https:\/\/doi.org\/10.1145\/3593856.3595892","DOI":"10.1145\/3593856.3595892"},{"key":"14_CR9","unstructured":"Jin, D., Atlidakis, V., Kemerlis, V.P.: EPF: Evil packet filter. In: 2023 USENIX Annual Technical Conference (USENIX ATC 23), pp. 735\u2013751. USENIX Association, Boston, MA (Jul 2023). https:\/\/www.usenix.org\/conference\/atc23\/presentation\/jin"},{"key":"14_CR10","unstructured":"Linus Torvalds: Linux kernel source repository. https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git. Accessed 18 May 2025"},{"key":"14_CR11","doi-asserted-by":"publisher","first-page":"194","DOI":"10.1007\/978-3-031-70896-1_10","volume-title":"Computer Security - ESORICS 2024","author":"Q Liu","year":"2024","unstructured":"Liu, Q., Shen, W., Zhou, J., Zhang, Z., Hu, J., Ni, S., Lu, K., Chang, R.: Interp-flow hijacking: Launching non-control data attack via hijacking ebpf interpretation flow. In: Garcia-Alfaro, J., Kozik, R., Chora\u015b, M., Katsikas, S. (eds.) Computer Security - ESORICS 2024, pp. 194\u2013214. Springer Nature Switzerland, Cham (2024)"},{"key":"14_CR12","unstructured":"MITRE Corporation: Common platform enumeration (cpe). https:\/\/cpe.mitre.org\/. Accessed 19 May 2025"},{"key":"14_CR13","unstructured":"MITRE Corporation: Cve - common vulnerabilities and exposures. https:\/\/www.cve.org\/. Accessed 19 May 2025"},{"key":"14_CR14","doi-asserted-by":"crossref","unstructured":"Mohamed, M.H.N., Wang, X., Ravindran, B.: Understanding the security of linux ebpf subsystem. In: Proceedings of the 14th ACM SIGOPS Asia-Pacific Workshop on Systems, pp. 87\u201392. APSys \u201923. Association for Computing Machinery, New York (2023). https:\/\/doi.org\/10.1145\/3609510.3609822","DOI":"10.1145\/3609510.3609822"},{"key":"14_CR15","doi-asserted-by":"publisher","unstructured":"Ponta, S.E., Plate, H., Sabetta, A., Bezzi, M., Dangremont, C.: A manually-curated dataset of fixes to vulnerabilities of open-source software. In: Proceedings of the 16th International Conference on Mining Software Repositories, pp. 383\u2013387. MSR \u201919, IEEE Press (2019).https:\/\/doi.org\/10.1109\/MSR.2019.00064","DOI":"10.1109\/MSR.2019.00064"},{"key":"14_CR16","doi-asserted-by":"publisher","unstructured":"Safronov, V., Bostan, I., Allott, N., Martin, A.: How memory-safe is iot? assessing the impact of memory-protection solutions for securing wireless gateways. In: Proceedings of the 14th International Conference on the Internet of Things, pp. 261\u2013266. IoT 2024. Association for Computing Machinery, New York (2025). https:\/\/doi.org\/10.1145\/3703790.3703820, https:\/\/doi.org\/10.1145\/3703790.3703820","DOI":"10.1145\/3703790.3703820"},{"key":"14_CR17","unstructured":"of\u00a0Standards, N.I., Technology: National vulnerability database. https:\/\/nvd.nist.gov (2025). https:\/\/nvd.nist.gov"},{"key":"14_CR18","doi-asserted-by":"crossref","unstructured":"Sun, H., Xu, Y., Liu, J., Shen, Y., Guan, N., Jiang, Y.: Finding correctness bugs in ebpf verifier with structured and sanitized program. In: Proceedings of the Nineteenth European Conference on Computer Systems. pp. 689\u2013703. EuroSys \u201924. Association for Computing Machinery, New York (2024). https:\/\/doi.org\/10.1145\/3627703.3629562","DOI":"10.1145\/3627703.3629562"},{"key":"14_CR19","unstructured":"The Linux Kernel Archives: Bpf - linux kernel documentation. https:\/\/docs.kernel.org\/bpf\/. Accessed 2025 19 May"},{"key":"14_CR20","unstructured":"The Linux Kernel Archives: Using cves to track security vulnerabilities in the linux kernel. https:\/\/docs.kernel.org\/process\/cve.html. Accessed 19 May 2025"},{"key":"14_CR21","doi-asserted-by":"publisher","first-page":"226","DOI":"10.1007\/978-3-031-37709-9_12","volume-title":"Computer Aided Verification","author":"H Vishwanathan","year":"2023","unstructured":"Vishwanathan, H., Shachnai, M., Narayana, S., Nagarakatte, S.: Verifying the verifier: ebpf range analysis verification. In: Enea, C., Lal, A. (eds.) Computer Aided Verification, pp. 226\u2013251. Springer, Cham (2023)"}],"container-title":["Lecture Notes in Computer Science","Risks and Security of Internet and Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-20732-6_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T10:28:16Z","timestamp":1784024896000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-20732-6_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032207319","9783032207326"],"references-count":21,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-20732-6_14","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"2 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRiSIS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Risks and Security of Internet and Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Gatineau, QC","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Canada","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 October 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 October 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crisis2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crisis2025.uqo.ca\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}