Executive brief
The Linux kernel's file system integrity verification (fsverity) component contains a memory-safety bug in BPF code that executes when verifying file digests. An attacker with local kernel access could trigger a crash by concurrently modifying memory while the function reads it, causing a denial of service. This affects systems using BPF-based file verification features.
Technical details
The vulnerability is a time-of-check-time-of-use (TOCTOU) race condition in the bpf_get_fsverity_digest() kfunc. The function reads the digest_size field from a BPF dynptr (a memory abstraction), but concurrent modifications to that memory location can cause the function to use stale or corrupted values, leading to out-of-bounds memory access and kernel crash. The fix involves using the hash algorithm's known-good digest_size value instead of the potentially unstable dynptr contents, and widening type annotations to u64 to match the dynptr size API return type. The vulnerability requires local code execution capable of invoking BPF kfuncs and performing concurrent memory modification.
Affected products
- Linux Linux kernel affected versions include at least Linux 5.19 and later (introduced in commit 67814c00de31)
Timeline
- 2026-08-22: disclosed
- 2026-08-19: patched