-

CVE-2026-90359

bpf: Reject >8 byte return values on return-reading trampoline paths

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject >8 byte return values on return-reading trampoline paths

btf_distill_func_proto() builds the function model used for the
fentry/fexit/fmod_ret/fsession trampolines and struct_ops. It has
accepted a 16-byte __int128 return value since the trampoline was
introduced: __get_type_size() returns the integer's type size, and the
return-type check only rejected ret < 0.

But the BPF trampoline preserves only 8 bytes of the return value (RAX on
x86, i.e. R0). For an attach type that reads the target's return value the
second half (RDX / R3) is neither saved nor restored, so a program
attached to a function returning a 16-byte value corrupts the value seen
by the real caller and itself observes only half of it. struct_ops
trampolines have the same limitation.

This affects the attach types that read the target's return value: fexit,
fmod_ret and fsession (plus the _multi variants of fexit and fsession),
and struct_ops. fentry/fentry_multi run before the target returns and are
unaffected.

Reject a >8 byte return value for these attach types in
bpf_check_attach_target() and bpf_check_attach_btf_id_multi(), and for
struct_ops in bpf_struct_ops_desc_init().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version fec56f5890d93fc2ed74166c397dc186b1c25951
Version < d36ac53fc83baf843c51b7afd6d2471f36b713d8
Status affected
Version fec56f5890d93fc2ed74166c397dc186b1c25951
Version < c48796aa6c392cde93946e5d5a9a1f1b1cf72feb
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.5
Status affected
Version 0
Version < 5.5
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.089
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d36ac53fc83baf843c51b7afd6d2471f36b713d8
https://git.kernel.org/stable/c/c48796aa6c392cde93946e5d5a9a1f1b1cf72feb