Executive brief
A vulnerability in the Linux kernel's BPF subsystem could allow a user with specific privileges to crash the system. By providing a specially crafted program with invalid data indices, an attacker can trigger a kernel panic, leading to a complete service outage. This affects systems where BPF debugging information is enabled, which is common in many major Linux distributions.
Technical details
A vulnerability exists in bpf_core_parse_spec() within the Linux kernel due to improper validation of CO-RE accessor indices. The function uses sscanf with a '%d' format specifier, which allows negative integers to be parsed. Subsequent bounds checks fail because C integer promotion causes negative values to appear smaller than the unsigned upper bound (btf_vlen). When these negative values are later cast to u32 in btf_member_bit_offset(), they result in a large out-of-bounds read. An attacker with CAP_BPF privileges can exploit this by loading a crafted BPF program, resulting in a deterministic kernel Oops/denial of service. The issue has been patched by explicitly rejecting negative indices immediately after parsing.
Affected products
- Linux Linux Kernel 7.0.0-rc6 and earlier versions
Timeline
- 2026-04-05: other: Patch authored
- 2026-05-27: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/1c22483a2c4bbf747787f328392ca3e68619c4dc
- https://git.kernel.org/stable/c/36a9012f76ba8d9189ae56a1f8bb7c87c07a1f3a
- https://git.kernel.org/stable/c/3ff85ae79e1a74baeb916b78a63d821f6d19a994
- https://git.kernel.org/stable/c/76f2ebaf79a9ae6d0737b87f045fe769e425d78f
- https://git.kernel.org/stable/c/99dbab7b5a12d8f58d5b0aa2f7a1fe656a70f4b2