7.8
CVE-2026-89580
- EPSS 0.13%
- Veröffentlicht 11.09.2026 19:44:46
- Zuletzt bearbeitet 13.09.2026 07:17:23
- Erkennungen
bpf: Disable preemption in __bpf_get_stack
In the Linux kernel, the following vulnerability has been resolved: bpf: Disable preemption in __bpf_get_stack get_perf_callchain() returns a per-CPU perf_callchain_entry buffer and releases its recursion slot via put_callchain_entry() before returning, so nothing keeps the entry reserved while __bpf_get_stack() consumes it below. A preemptible BPF program (e.g. a non-sleepable raw tracepoint program on a PREEMPT kernel, which runs under migrate_disable() but not preempt_disable()) can be scheduled out between obtaining the entry and the copy. Another task scheduled on the same CPU then reuses the same per-CPU buffer and overwrites trace->nr with a larger value. copy_len is then computed from the inflated trace->nr and can exceed the caller's buffer, causing an out-of-bounds write in the memcpy() and in the build_id path. The rcu_read_lock() taken here alone does not prevent this. It is only taken on the may_fault path, and under CONFIG_PREEMPT_RCU it does not disable preemption; it merely keeps perf's callchain buffer array alive (freed via call_rcu()) and does nothing to stop another task from reusing the entry. Disable preemption around obtaining the callchain entry and copying it into the caller's buffer, so the entry cannot be reused underneath us and trace->nr stays bounded by max_depth. Build ID resolution may fault and is therefore deferred until after preemption is re-enabled; by then the instruction pointers have already been copied into buf, so it operates only on that private copy. Note, preempt_disable() also subsumes the buffer-lifetime guarantee the rcu_read_lock() provided, since a preempt-disabled section is an RCU read-side critical section for the callchain buffers' call_rcu() reclaim. [ changed Fixes: commit ]
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
c195651e565ae7f41a68acb7d4aa7390ad215de1
Version <
8c5ba022f2085ea42d011497a6e92e527d123b9b
Status
affected
Version
c195651e565ae7f41a68acb7d4aa7390ad215de1
Version <
dbfecc8a6631c0d3626c14ba1f1a485a4498445a
Status
affected
Version
c195651e565ae7f41a68acb7d4aa7390ad215de1
Version <
9a23747909fcae707990c8466c381a0e7acfaa4e
Status
affected
Version
c195651e565ae7f41a68acb7d4aa7390ad215de1
Version <
b1a47b2708d4e95dbd23aee2ec83752190897b3f
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
4.18
Status
affected
Version
0
Version <
4.18
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.028 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/8c5ba022f2085ea42d011497a6e92e527d123b9b
https://git.kernel.org/stable/c/dbfecc8a6631c0d3626c14ba1f1a485a4498445a
https://git.kernel.org/stable/c/9a23747909fcae707990c8466c381a0e7acfaa4e
https://git.kernel.org/stable/c/b1a47b2708d4e95dbd23aee2ec83752190897b3f