PT-2026-94908 · Linux · Linux Kernel

CVE-2026-93112

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the BPF subsystem where the bpf cpumask populate() function uses bitmap copy() to write to a destination typed as struct cpumask *. This allows the verifier to incorrectly accept borrowed cpumask pointers returned by read-only kfuncs, such as scx bpf get online cpumask(), as writable destinations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-93112
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel