PT-2026-84842 · Prevail · Prevail
CVE-2026-53706
·
Published
2026-09-02
·
Updated
2026-09-02
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
PREVAIL versions prior to 0.2.4
Description
The eBPF verifier fails to check the
is64 flag when processing ALU32 ADD and SUB instructions that operate on pointer-typed registers. Since ALU32 arithmetic zero-extends the 32-bit result, the upper half of the pointer is destroyed during runtime, even though the verifier marks the program as safe. This allows users who can submit eBPF programs for verification, including unprivileged users on compatible kernels, to create programs that pass verification but may fault or misbehave during execution.Recommendations
Update to version 0.2.4.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prevail