PT-2026-94793 · Linux · Linux Kernel
CVE-2026-92485
·
Published
2026-09-17
·
Updated
2026-09-28
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the BPF subsystem where the trampoline could be corrupted due to the incorrect assignment of
tr->flags in the verifier. When a fexit is attached to a tail call reachable program, the tr->flags variable may be overwritten, causing the trampoline to use a jump instruction instead of a call instruction when poking the target program's nop instruction. This leads to a failure in restoring the nop instruction when the fexit link is closed, resulting in a kernel warning in the bpf tracing link release() function.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel