Junglewise Threat Intelligence

CVE-2026-80607: Linux kernel tracing/probes WARN_ON_ONCE removal in parse_btf_arg

CVE-2026-80607 · Severity: info · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's tracing subsystem includes a kprobe facility that allows dynamic instrumentation of kernel functions. A WARN_ON_ONCE() macro in the BTF parameter parsing code was triggering on legitimate user operations when adding kprobe events with raw addresses, causing unnecessary kernel warnings. The fix removes this overly strict validation check that was incorrectly flagging normal usage patterns.

Technical details

The vulnerability is a false-positive diagnostic in the parse_btf_arg() function within kernel/trace/trace_probe.c. The WARN_ON_ONCE() macro was unconditionally triggering when users attempted to create kprobe events based on raw addresses with BTF parameter information, even though this is a valid and expected use case. The fix simply removes the WARN_ON_ONCE() wrapper around the condition while retaining the error return logic, allowing the function to validate and return -EINVAL appropriately without generating spurious kernel warnings. This is a defensive programming correction rather than a security patch.

Affected products

  • Linux Linux kernel 5.x, 6.x, 7.x (and later versions with the affected code)

Timeline

  • 2026-08-28: disclosed: Published in NVD
  • 2026-06-25: patched: Upstream fix merged by Masami Hiramatsu

References

Related threats