Junglewise Threat Intelligence

CVE-2026-64353: Linux kernel BPF verifier nullness elision bypass in ARRAY_OF_MAPS

CVE-2026-64353 · Severity: info · CVSS 5.5 · Published 2026-07-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's BPF (Berkeley Packet Filter) subsystem, which is used for high-performance networking and system monitoring. Under specific conditions involving nested data structures, the system could incorrectly assume a data lookup will always succeed, leading to a potential system crash or instability. This issue primarily affects system availability and operational stability.

Technical details

A vulnerability exists in the Linux kernel BPF verifier's handling of ARRAY_OF_MAPS. When an inner map is created with BPF_F_INNER_MAP, it serves as a template, but concrete inner arrays can have different max_entries values. The verifier incorrectly used the template's max_entries to elide nullness checks for constant-key lookups, even though the runtime map might have a smaller size. This logic error allows a BPF program to bypass null pointer checks for lookup results that could actually be null at runtime. The fix ensures that lookup results for maps marked with BPF_F_INNER_MAP remain nullable in the verifier's state. Patches have been backported to various stable branches including 6.18.x and 7.1.x.

Affected products

  • Linux Linux 6.14 to 7.2-rc1

Timeline

  • 2026-06-07: other: Initial patch submitted
  • 2026-07-24: patched: Patch committed to stable tree
  • 2026-07-25: disclosed: CVE published

References