Executive brief
PREVAIL is an eBPF program verifier that uses abstract interpretation to ensure programs are safe before kernel execution. A flaw in its abstract transformer allows attackers to craft eBPF programs that overwrite read-only context fields (such as packet data pointers) and dereference arbitrary addresses, while the verifier incorrectly reports the malicious program as safe. This undermines the security guarantees of eBPF sandboxing and could allow kernel memory corruption.
Technical details
The vulnerability is a logic error in PREVAIL's abstract transformer (src/crab/ebpf_transformer.cpp). The do_mem_store function only models T_STACK stores and ignores writes through T_CTX-typed base registers, treating them as silent no-ops. Additionally, the T_CTX case in the ValidAccess checker never inspects AccessType::write, only the default read operation. An attacker can craft an eBPF program that writes to a context field like ctx->data (which should be read-only), then reload that field as a typed packet pointer, and dereference an attacker-controlled address. PREVAIL's soundness check will pass the program despite the unsafe operation. The vulnerability was patched in version 0.2.4 by adding logic to reject writes that overlap read-only pointer slots while allowing writes to scalar context fields.
Affected products
- vbpf PREVAIL before 0.2.4
Timeline
- 2026-09-02: disclosed
- 2026-06-01: patched