Junglewise Threat Intelligence

CVE-2026-31413: Linux Kernel out-of-bounds access in BPF verifier

CVE-2026-31413 · Severity: high · CVSS 7.8 · Published 2026-04-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's BPF subsystem could allow a local attacker to bypass security checks. The BPF verifier, which ensures that custom programs uploaded to the kernel are safe, incorrectly calculates the results of certain mathematical operations. This error can be exploited to gain unauthorized access to restricted memory, potentially leading to a full system compromise or data theft.

Technical details

A logic error exists in the maybe_fork_scalars() function within the Linux kernel's BPF verifier. When processing BPF_OR instructions with a constant source operand and a destination register in the signed range [-1, 0], the verifier incorrectly forks the state, tracking the destination as 0 in the pushed path when the actual runtime value is K. This verifier/runtime divergence allows an attacker to bypass safety checks and perform out-of-bounds map accesses. The fix involves passing the current instruction index to push_stack() so the pushed path re-executes the ALU instruction with the correct register state. Patches have been released for multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 6.12.75 to 6.12.80, 6.18.16 to 6.18.21, 6.19.6 to 6.19.11

Timeline

  • 2026-03-14: other: Vulnerability reported by Daniel Wade
  • 2026-04-12: disclosed: CVE published
  • 2026-04-02: patched: Patches committed to stable trees

References

Related threats