PT-2026-51975 · Linux+2 · Linux Kernel+2
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the Berkeley Packet Filter (BPF) verifier within the
regsafe() function. The issue occurs when comparing two scalar registers that both carry BPF ADD CONST values; the check scalar ids() function maps their full compound IDs as a single entry but fails to verify that the underlying base IDs are consistent with existing mappings. This inconsistency allows for the construction of verifier states where state pruning incorrectly succeeds, potentially enabling a bypass of security mechanisms and allowing unauthorized operations or unexpected system behavior.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu