7.8

CVE-2026-72427

bpf: Fix effective prog array index with BPF_F_PREORDER

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix effective prog array index with BPF_F_PREORDER

replace_effective_prog() and purge_effective_progs() located the slot in
the effective array by walking the program hlist and counting entries
linearly. That count does not match the array layout: compute_effective_
progs() places BPF_F_PREORDER programs at the front (ancestor cgroup
first, attach order within a cgroup) and the rest after them (descendant
cgroup first). So when a preorder program is present, the linear hlist
position no longer equals the program's index in the effective array.

For replace_effective_prog() (bpf_link_update()) this overwrote the
wrong slot, corrupting the effective order. For purge_effective_progs(),
it could dummy out a slot belonging to a different program and leave the
detached program in the array while bpf_prog_put() drops its reference,
i.e. a use-after-free.

Fix both by replaying compute_effective_progs()'s placement (including
the per-cgroup preorder reversal) in a shared effective_prog_pos()
helper. Identify the entry by its struct bpf_prog_list pointer rather
than by (prog, link) value, so the lookup resolves to exactly the
attachment the syscall selected even when the same bpf_prog is attached
to several cgroups in the hierarchy.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version bc8023ef3b11410682e5d4990e05e5bc2d3e1c94
Version < 525e408c27ae714e538b8c608c3a974df3ab6c92
Status affected
Version 555c0b713ca83968d3c843cb15485b9ba3367b1b
Version < 41b4320b84fdafe1ab586b06453d30d50415db59
Status affected
Version 4b82b181a26cff8bf7adc3a85a88d121d92edeaf
Version < 9697db03e010391c55ae75192cbdf30c5a72c114
Status affected
Version 4b82b181a26cff8bf7adc3a85a88d121d92edeaf
Version < b584f107ab90222bd825dcb4c5977326ff684109
Status affected
Version 4b82b181a26cff8bf7adc3a85a88d121d92edeaf
Version < f08aaee3152d0dfc578b3f2586932d82062701dd
Status affected
Version 4707ad649cf662add3058bff47430817811b048d
Status affected
Version 6.6.93
Version < 6.6.145
Status affected
Version 6.12.31
Version < 6.12.97
Status affected
Version 6.14.9
Version < 6.15
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.15
Status affected
Version 0
Version < 6.15
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.034
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/525e408c27ae714e538b8c608c3a974df3ab6c92
https://git.kernel.org/stable/c/41b4320b84fdafe1ab586b06453d30d50415db59
https://git.kernel.org/stable/c/9697db03e010391c55ae75192cbdf30c5a72c114
https://git.kernel.org/stable/c/b584f107ab90222bd825dcb4c5977326ff684109
https://git.kernel.org/stable/c/f08aaee3152d0dfc578b3f2586932d82062701dd