PT-2026-94793 · Linux · Linux Kernel

CVE-2026-92485

·

Published

2026-09-17

·

Updated

2026-09-28

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the BPF subsystem where the trampoline could be corrupted due to the incorrect assignment of tr->flags in the verifier. When a fexit is attached to a tail call reachable program, the tr->flags variable may be overwritten, causing the trampoline to use a jump instruction instead of a call instruction when poking the target program's nop instruction. This leads to a failure in restoring the nop instruction when the fexit link is closed, resulting in a kernel warning in the bpf tracing link release() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102357
CVE-2026-92485
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel