Junglewise Threat Intelligence

CVE-2026-45839: Linux Kernel out-of-bounds read in BPF CO-RE parser

CVE-2026-45839 · Severity: info · CVSS 6.2 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's BPF subsystem could allow a user with specific privileges to crash the system. By providing a specially crafted program with invalid data indices, an attacker can trigger a kernel panic, leading to a complete service outage. This affects systems where BPF debugging information is enabled, which is common in many major Linux distributions.

Technical details

A vulnerability exists in bpf_core_parse_spec() within the Linux kernel due to improper validation of CO-RE accessor indices. The function uses sscanf with a '%d' format specifier, which allows negative integers to be parsed. Subsequent bounds checks fail because C integer promotion causes negative values to appear smaller than the unsigned upper bound (btf_vlen). When these negative values are later cast to u32 in btf_member_bit_offset(), they result in a large out-of-bounds read. An attacker with CAP_BPF privileges can exploit this by loading a crafted BPF program, resulting in a deterministic kernel Oops/denial of service. The issue has been patched by explicitly rejecting negative indices immediately after parsing.

Affected products

  • Linux Linux Kernel 7.0.0-rc6 and earlier versions

Timeline

  • 2026-04-05: other: Patch authored
  • 2026-05-27: advisory: NVD publication date

References

Related threats