Executive brief
A vulnerability was identified in the Linux kernel's resource tracking system (cgroup rstat). A local attacker with specific administrative privileges could provide an invalid processor ID to the system, potentially causing the kernel to crash or behave unpredictably. This issue primarily affects system stability and could be used to disrupt operations on the affected server.
Technical details
An out-of-bounds (OOB) array access vulnerability exists in 'kernel/cgroup/rstat.c' within the Linux kernel. The 'css_rstat_updated()' function, which is exposed as a BPF kfunc, accepts a caller-provided CPU argument and uses it for per-CPU rstat lookups without verifying if the index refers to a valid possible CPU. A local attacker with CAP_BPF and CAP_PERFMON privileges can trigger this by passing an invalid CPU value (e.g., 0x7fffffff), resulting in a kernel crash (UBSAN: array-index-out-of-bounds). The fix introduces CPU validation in the BPF-facing wrapper and moves the core logic to an internal function for trusted in-kernel callers.
Affected products
- Linux Linux Kernel 6.1, 6.18.34, 7.0.11, 7.1
Timeline
- 2026-05-16: other: Patch authored
- 2026-07-19: disclosed: CVE published