Executive brief
The Linux kernel's BPF program query mechanism writes kernel data beyond the boundaries of user-provided buffers when older userspace applications pass smaller data structures than the kernel expects. This can expose sensitive kernel memory or cause system crashes. The issue affects cgroup-based BPF query operations and impacts systems running Linux kernels with the vulnerable code.
Technical details
The vulnerability is an out-of-bounds (OOB) write in the BPF_PROG_QUERY syscall handler. The kernel unconditionally writes the 'query.revision' field to userspace without checking whether the user-provided buffer size is large enough to accommodate it. When a userspace application passes a smaller 'bpf_attr' structure (e.g., 40 bytes from pre-revision builds), the kernel writes beyond buffer boundaries. The fix propagates the user-provided attribute size down to cgroup query handlers and conditionally skips writing the revision field when the buffer is insufficient. This issue specifically affects cgroup-attached BPF programs, as tcx and netkit attach types were introduced concurrently with the revision field. A local user with CAP_SYS_ADMIN or equivalent capability can trigger this via the bpf() syscall.
Affected products
- Linux Linux kernel
Timeline
- 2026-08-15: disclosed
- 2026-08-15: advisory