Junglewise Threat Intelligence

CVE-2026-45837: Linux Kernel use-after-free in BPF arena_vm_close on fork

CVE-2026-45837 · Severity: info · CVSS 0 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) component could allow a local attacker to crash the system or potentially execute unauthorized code. The issue occurs when a process using a specific type of shared memory (BPF arena) creates a child process; the system fails to properly track memory ownership between the two, leading to a 'use-after-free' error. This could result in system instability or a complete service outage.

Technical details

A use-after-free vulnerability was identified in the BPF arena implementation within the Linux kernel. The issue stems from arena_vm_open() incrementing the mmap_count without registering child Virtual Memory Areas (VMAs) in the arena's VMA list. Consequently, the vml->vma pointer continues to reference the parent VMA; if the parent performs an munmap, the pointer becomes dangling. A subsequent call to bpf_arena_free_pages() by the child process triggers a use-after-free during zap_pages(). The fix involves setting the VM_DONTCOPY flag to prevent arena VMA inheritance across forks and implementing callbacks to reject VMA splits and mremap operations.

Affected products

  • Linux Linux Kernel Introduced in 317460317a02 (bpf_arena)

Timeline

  • 2026-04-13: patched: Initial patch by Alexei Starovoitov
  • 2026-05-27: disclosed: CVE-2026-45837 published

References