Executive brief
A vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) component could allow a local attacker to crash the system or potentially execute unauthorized code. The issue occurs when a process using a specific type of shared memory (BPF arena) creates a child process; the system fails to properly track memory ownership between the two, leading to a 'use-after-free' error. This could result in system instability or a complete service outage.
Technical details
A use-after-free vulnerability was identified in the BPF arena implementation within the Linux kernel. The issue stems from arena_vm_open() incrementing the mmap_count without registering child Virtual Memory Areas (VMAs) in the arena's VMA list. Consequently, the vml->vma pointer continues to reference the parent VMA; if the parent performs an munmap, the pointer becomes dangling. A subsequent call to bpf_arena_free_pages() by the child process triggers a use-after-free during zap_pages(). The fix involves setting the VM_DONTCOPY flag to prevent arena VMA inheritance across forks and implementing callbacks to reject VMA splits and mremap operations.
Affected products
- Linux Linux Kernel Introduced in 317460317a02 (bpf_arena)
Timeline
- 2026-04-13: patched: Initial patch by Alexei Starovoitov
- 2026-05-27: disclosed: CVE-2026-45837 published