Junglewise Threat Intelligence

CVE-2026-43306: Linux Kernel BPF crypto CFI failure in destructor kfunc

CVE-2026-43306 · Severity: medium · CVSS 5.5 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem can cause a system crash when Control Flow Integrity (CFI) is enabled. The issue occurs during cryptographic operations when the system attempts to release memory using an incorrectly typed function. This results in a kernel 'oops' or crash, potentially leading to a denial of service for the affected system.

Technical details

A vulnerability exists in the Linux kernel's BPF crypto component where an incorrect function pointer type is used for a destructor kfunc. When CONFIG_CFI is enabled, the kernel enforces strict type matching for indirect function calls. The function bpf_crypto_ctx_release was being called in a context expecting a different signature, specifically during bpf_obj_free_fields. This mismatch triggers a CFI failure and a subsequent kernel panic (Oops). The fix involves introducing a stub function, bpf_crypto_ctx_release_dtor, with the correct 'void *' argument type to satisfy both the BPF verifier and CFI requirements.

Affected products

  • Linux Linux Kernel 6.1, 6.6, 6.7, 6.8

Timeline

  • 2026-01-10: other: Patch authored
  • 2026-05-08: disclosed: CVE published

References

Related threats