Executive brief
A vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem could allow a local attacker to cause a system crash or potentially execute unauthorized code. The issue occurs when the system processes specially crafted data structures used for program debugging and tracing. This could impact the stability of the operating system and the security of data handled by the kernel.
Technical details
A heap buffer overflow exists in the Linux kernel's BPF component within the btf_repeat_fields() function. When processing user-supplied BPF Type Format (BTF) data during a BPF_BTF_LOAD operation, the kernel fails to properly validate field counts due to an integer overflow in a u32 calculation. Specifically, a malformed BTF can cause the expanded field count calculation to wrap around, bypassing capacity checks for the fixed-size BTF_FIELDS_MAX scratch array. This leads to an out-of-bounds write during a subsequent memcpy() operation. The vulnerability has been addressed by implementing checked addition and multiplication (check_add_overflow and check_mul_overflow) to validate field counts before expansion.
Affected products
- Linux Linux 6.11.6 to 6.12, 6.12.96, 6.18.39, 7.1.4
Timeline
- 2026-06-05: other: Vulnerability fixed in upstream kernel source
- 2026-07-25: advisory: CVE-2026-64354 published