PT-2026-94921 · Linux · Linux Kernel
CVE-2026-93125
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the BPF subsystem where the
check kfunc args() function fails to bound kfunc arguments named rdonly buf size or rdwr buf size. These values are stored in meta->r0 size (a u64) and subsequently copied into the mem size field of the returned register, which is a u32. If a constant with upper 32 bits set is used, it is truncated rather than rejected during load-time. This leads the verifier to record a PTR TO MEM register with an incorrect memory size, causing subsequent access checks to use a truncated and invalid bound.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel