PT-2026-97957 · Linux · Linux
CVE-2026-93270
·
Published
2026-09-24
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Disallow interpreter fallback for BPF ADDR PERCPU insn
The BPF MOV64 PERCPU REG insn requires JIT to emit native code to for
'dst reg = src reg + '.
However, the interpreter ignores the 'off' at its ALU64 MOV X label.
The 'off' indicates the insn is BPF MOV64 PERCPU REG insn. Then, when
the interpreter loads memory from the register, it will hit a page
fault.
[ 2.545572] BUG: unable to handle page fault for address: ffffffffacaaf034
[ 2.546485] #PF: supervisor read access in kernel mode
[ 2.547167] #PF: error code(0x0000) - not-present page
[ 2.547850] PGD 134e63067 P4D 134e63067 PUD 134e64063 PMD 10021c063 PTE 800ffffeca550062
[ 2.548912] Oops: Oops: 0000 [#1] SMP PTI
Set jit required as true in order to disallow interpreter fallback in
core.c:: bpf prog select runtime(), if any BPF ADDR PERCPU insn is
patched to the prog.
BTW, rename the helper bpf map supports cpu flags() to
bpf map is percpu map().
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux