7.8

CVE-2026-89579

bpf: Harden bloom filter sizing and indexing on 32-bit kernels

In the Linux kernel, the following vulnerability has been resolved:

bpf: Harden bloom filter sizing and indexing on 32-bit kernels

bloom_map_alloc() has two 32-bit-specific problems when the computed
bitmap reaches the U32_MAX fallback case.

First, BITS_TO_BYTES(U32_MAX) is evaluated with 32-bit arithmetic. The
addition performed by DIV_ROUND_UP wraps, so the map allocates only the
fixed-size bloom filter object while keeping bitset_mask == U32_MAX.
Subsequent updates can then write past the allocated object.

Second, fixing only the allocation size is not sufficient. The bloom hash
is a u32, but set_bit() takes a signed long bit number and x86 test_bit()
eventually feeds the index to variable_test_bit(long, ...). On 32-bit
kernels, hashes in [0x80000000, U32_MAX] therefore become negative bit
offsets. x86 bt/bts with a memory operand interpret those offsets relative
to the supplied base, so a map with bitset_mask == U32_MAX can read or
write before bloom->bitset even after allocating the full 512 MiB bitmap.

Keep the U32_MAX fallback, but split each hash into a word pointer and an
in-word bit number before calling test_bit() or set_bit(). The bitops
argument is then always in [0, BITS_PER_LONG - 1], while BIT_WORD(h) still
selects the intended word in the full bitmap.

Compute the bitset size from (u64)bitset_mask + 1 before passing the final
size to bpf_map_area_alloc(). This fixes the original under-allocation and
keeps the allocated storage consistent with the addressable bitset.

Exploitation note: local privilege escalation is possible on a 32-bit x86
kernel using the under-allocation bug from a binary with CAP_BPF.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 9330986c03006ab1d33d243b7cfe598a7a3c1baa
Version < a6183bc683f97f4317f7e84939ca7fff37c5688b
Status affected
Version 9330986c03006ab1d33d243b7cfe598a7a3c1baa
Version < 80551bf8912c42d1e3d55eec6fa3c40f306c3de8
Status affected
Version 9330986c03006ab1d33d243b7cfe598a7a3c1baa
Version < 3b7a13eccfcf97714ffc1ca6aa663d66d4a30e29
Status affected
Version 9330986c03006ab1d33d243b7cfe598a7a3c1baa
Version < 272fcb4ba6fab678db0eb966dc81c4c804bef64a
Status affected
Version 9330986c03006ab1d33d243b7cfe598a7a3c1baa
Version < dff481e12b3f127739f6a4ea7cef2c25dc12e056
Status affected
Version 9330986c03006ab1d33d243b7cfe598a7a3c1baa
Version < 11c1e836710dcba03e50454a4eedfdbaf8d3050e
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.16
Status affected
Version 0
Version < 5.16
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.062
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3b7a13eccfcf97714ffc1ca6aa663d66d4a30e29
https://git.kernel.org/stable/c/272fcb4ba6fab678db0eb966dc81c4c804bef64a
https://git.kernel.org/stable/c/dff481e12b3f127739f6a4ea7cef2c25dc12e056
https://git.kernel.org/stable/c/11c1e836710dcba03e50454a4eedfdbaf8d3050e
https://git.kernel.org/stable/c/80551bf8912c42d1e3d55eec6fa3c40f306c3de8
https://git.kernel.org/stable/c/a6183bc683f97f4317f7e84939ca7fff37c5688b