Junglewise Threat Intelligence

CVE-2026-53094: Linux Kernel use-after-free in BPF offload during constant blinding

CVE-2026-53094 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's BPF subsystem, which handles specialized programs used for networking and security. Under specific configurations where security hardening is enabled, the system may incorrectly track internal memory pointers when these programs are compiled. This can lead to a system crash (page fault) when a network interface is shut down or a network namespace is deleted, potentially causing a denial-of-service.

Technical details

A use-after-free vulnerability exists in the Linux kernel BPF subsystem when using device-bound-only XDP programs (BPF_F_XDP_DEV_BOUND_ONLY) with JIT constant blinding enabled (bpf_jit_harden >= 2). When constant blinding is active, bpf_jit_blind_constants() clones the BPF program and frees the original; however, the kernel fails to update the 'offload->prog' back-pointer to the new clone. This results in a stale pointer to freed memory. When the associated network namespace is destroyed, the cleanup process attempts to access this pointer via __bpf_prog_offload_destroy(), leading to a kernel page fault and system crash. The issue has been resolved by ensuring 'offload->prog' is updated alongside 'aux->prog' during the program release/replacement phase.

Affected products

  • Linux Linux Kernel 2b3486bc2d23 to a713b72ff88cdab4d5d692908ab1259ada511f4d

Timeline

  • 2026-04-05: patched: Mainline patch applied
  • 2026-06-24: disclosed: CVE published

References

Related threats