Executive brief
A vulnerability in the Linux kernel's eBPF (extended Berkeley Packet Filter) subsystem affects network packet filtering and connection tracking operations. When BPF programs perform connection tracking lookups or allocations with incorrectly sized options structures, the kernel could write error information outside the bounds of memory that the security verifier intended to allow, potentially leading to memory corruption or privilege escalation.
Technical details
The vulnerability exists in the BPF conntrack helper functions (bpf_xdp_ct_lookup, bpf_xdp_ct_alloc, bpf_skb_ct_lookup, bpf_skb_ct_alloc) in net/netfilter/nf_conntrack_bpf.c. The functions accept an opts pointer and opts__sz size argument; the verifier checks only the memory range indicated by opts__sz, but the code unconditionally wrote to opts->error field on lookup/allocation failures. When an invalid opts__sz smaller than the offset of the error field was supplied, the write would land outside the verifier-checked memory range, enabling out-of-bounds writes. The fix adds a helper function bpf_ct_opts_result() that only writes opts->error when opts__sz is large enough to include that field. Exploitation requires loading a malicious BPF program (local attack vector), as BPF programs can only be loaded by privileged users; however, once loaded, the out-of-bounds write could be leveraged for privilege escalation or memory corruption.
Affected products
- Linux Linux kernel 5.8 and later before patched versions
Timeline
- 2026-08-15: disclosed: Published on NVD
- 2026-06-22: patched: Patch committed upstream (6f6183a39533d727deaa5061cadae6dd9e6744d0)
- 2026-07-24: other: Backported to stable kernels (dd74c80203842a21b2ebb9f70d1260d9aa20fa05)