8.8

CVE-2026-72111

bpf: Reset register bounds before narrowing retval range in check_mem_access()

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reset register bounds before narrowing retval range in check_mem_access()

When the BPF verifier processes a context load of an LSM hook return
value, it calls __mark_reg_s32_range() to narrow the register to the
hook's valid range. However, __mark_reg_s32_range() intersects the new
range with the register's existing bounds using max_t()/min_t() rather
than replacing them.

If the destination register carries stale bounds from a prior instruction
(e.g. BPF_MOV64_IMM), the intersection can produce a range narrower than
reality. The verifier then believes it knows the register's exact value,
while at runtime the actual hook return value is loaded, creating a
verifier/runtime mismatch that can be used to bypass BPF memory safety
checks.

The else branch already calls mark_reg_unknown() to reset register state
before any narrowing. Apply the same reset in the is_retval path so
stale bounds are cleared before __mark_reg_s32_range() intersects.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 5d99e198be279045e6ecefe220f5c52f8ce9bfd5
Version < bde92f65042ec14389782dd223f706bf6b59ce5d
Status affected
Version 5d99e198be279045e6ecefe220f5c52f8ce9bfd5
Version < 0993dc5fc619c0b25ab1310cb11d65e78351c0fe
Status affected
Version 5d99e198be279045e6ecefe220f5c52f8ce9bfd5
Version < 5a55f9aecc08990940e70f0c7048a80850c5a16a
Status affected
Version 5d99e198be279045e6ecefe220f5c52f8ce9bfd5
Version < 5e0b273e0a62cc04ec338c7b502797c66c2ed42a
Status affected
Version 1050727d83e70449991c29dd1cf29fe936a63da3
Status affected
Version 27ca3e20fe80be85a92b10064dfeb56cb2564b1c
Status affected
Version 6.10.13
Version < 6.11
Status affected
Version 6.11.2
Version < 6.12
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.12
Status affected
Version 0
Version < 6.12
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.069
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/bde92f65042ec14389782dd223f706bf6b59ce5d
https://git.kernel.org/stable/c/0993dc5fc619c0b25ab1310cb11d65e78351c0fe
https://git.kernel.org/stable/c/5a55f9aecc08990940e70f0c7048a80850c5a16a
https://git.kernel.org/stable/c/5e0b273e0a62cc04ec338c7b502797c66c2ed42a