Junglewise Threat Intelligence

CVE-2026-74371: Linux kernel BPF_PROG_QUERY out-of-bounds write in cgroup handlers

CVE-2026-74371 · Severity: high · CVSS 7.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's BPF program query mechanism writes kernel data beyond the boundaries of user-provided buffers when older userspace applications pass smaller data structures than the kernel expects. This can expose sensitive kernel memory or cause system crashes. The issue affects cgroup-based BPF query operations and impacts systems running Linux kernels with the vulnerable code.

Technical details

The vulnerability is an out-of-bounds (OOB) write in the BPF_PROG_QUERY syscall handler. The kernel unconditionally writes the 'query.revision' field to userspace without checking whether the user-provided buffer size is large enough to accommodate it. When a userspace application passes a smaller 'bpf_attr' structure (e.g., 40 bytes from pre-revision builds), the kernel writes beyond buffer boundaries. The fix propagates the user-provided attribute size down to cgroup query handlers and conditionally skips writing the revision field when the buffer is insufficient. This issue specifically affects cgroup-attached BPF programs, as tcx and netkit attach types were introduced concurrently with the revision field. A local user with CAP_SYS_ADMIN or equivalent capability can trigger this via the bpf() syscall.

Affected products

  • Linux Linux kernel

Timeline

  • 2026-08-15: disclosed
  • 2026-08-15: advisory

Related threats