Executive brief
A vulnerability was identified in the Linux kernel's BPF (Berkeley Packet Filter) verifier, a component responsible for ensuring that custom network and system programs are safe to run. The issue involves how the verifier tracks data ranges during specific logical operations, which could lead to internal kernel errors or crashes. While primarily affecting Linux-based systems, this also impacts certain industrial controllers from Siemens that utilize affected kernel versions.
Technical details
A range invariant violation exists in the Linux kernel BPF verifier's handling of the JSET instruction. When the verifier refines register bounds (tnums) after a JSET, it may fail to recognize unreachable code paths, leading to inconsistent register states where the minimum value exceeds the maximum value (e.g., umin=1, umax=0). This occurs because the verifier's branch tracking (is_branch_taken) does not correctly account for sign extensions during JSET operations. An attacker with the ability to load BPF programs could trigger this invariant violation, leading to kernel warnings or potential denial-of-service. The fix involves marking registers as unbounded (__mark_reg_unbounded) before narrowing tnums after a JSET to prevent inconsistent states.
Affected products
- Linux Linux Kernel 6.8 to 6.12 (fixed in various stable branches)
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
Timeline
- 2025-07-10: disclosed: Initial patch authored by Paul Chaignon
- 2025-09-11: advisory: CVE published
- 2026-03-25: patched: Patch committed to stable tree by Greg Kroah-Hartman
References
- https://git.kernel.org/stable/c/0643aa2468192a4d81326e8e76543854870b1ee2
- https://git.kernel.org/stable/c/22191359f8454b0be082c3b126f86bcbea0f1318
- https://git.kernel.org/stable/c/2fd0c26bacd90ef26522bd3169000a4715bf151f
- https://git.kernel.org/stable/c/591c788d16046edb0220800bf1819554af5853ce
- https://git.kernel.org/stable/c/6279846b9b2532e1b04559ef8bd0dec049f29383
- https://git.kernel.org/stable/c/80a6b11862a7cfdf691e8f9faee89cfea219f098
- https://git.kernel.org/stable/c/c29dd8336236a4deb75596b52d2dd16ccc4a380d