Executive brief
A vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem could allow a local user to strain system resources. By providing an excessively large signature size for a BPF program, an attacker can force the kernel to perform expensive memory allocation operations. This could lead to degraded system performance or a denial-of-service condition.
Technical details
A vulnerability in 'kernel/bpf/syscall.c' within the Linux kernel's BPF subsystem allowed for unbounded signature sizes in 'bpf_prog_verify_signature'. An attacker could provide a 'signature_size' value exceeding 'KMALLOC_MAX_CACHE_SIZE', forcing the kernel to use 'kmalloc_large' or 'vmalloc' allocation paths. This lack of input validation can be abused to trigger expensive memory management operations, potentially leading to local denial-of-service or resource exhaustion. The fix introduces a check to ensure 'attr->signature_size' does not exceed the maximum cache size, returning '-EINVAL' if it does.
Affected products
- Linux Linux Kernel Fixed in versions 5835a07, ea1535e, eb8166c
Timeline
- 2026-02-05: other: Vulnerability reported and initial patch authored
- 2026-05-27: disclosed: CVE published to NVD