7.8

CVE-2026-92485

bpf: Fix WARNING in bpf_tracing_link_release

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix WARNING in bpf_tracing_link_release

The trampoline could be corrupted by the blindly
'tr->flags = BPF_TRAMP_F_TAIL_CALL_CTX' in verifier.

1. A fexit attached to a tail_call_reachable prog. 'tr->flags' became
   'BPF_TRAMP_F_CALL_ORIG | BPF_TRAMP_F_TAIL_CALL_CTX'. And, the
   trampoline would poke the target prog's nop insn using jmp insn instead
   of call insn.
2. Another fexit loaded with the same tail_call_reachable prog target.
   'tr->flags' became 'BPF_TRAMP_F_TAIL_CALL_CTX'.
3. Close the first fexit link. Due to no BPF_TRAMP_F_CALL_ORIG in
   'tr->flags', the trampoline will fail to restore the prog's nop insn
   using call insn.

[    3.410719] WARNING: kernel/bpf/syscall.c:3551 at bpf_tracing_link_release+0x53/0x60, CPU#1: test_progs/98
...
[    3.428793]  bpf_link_free+0x58/0x130
[    3.429293]  bpf_link_release+0x23/0x30

Fix the warning by updating 'tr->flags' with '|=' and lock.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 2b5dcb31a19a2e0acd869b12c9db9b2d696ef544
Version < 48a0209d8da0d90a7b0a0db19d1ff88027b13781
Status affected
Version 2b5dcb31a19a2e0acd869b12c9db9b2d696ef544
Version < 61aaa8782bec59ecffd22e030f54ef9351bcabf9
Status affected
Version 605c8d8f9966fcd2f0b858fabebe416fc83f2209
Status affected
Version 028480eaf2a1401e914a1fa1a4a21d877cf0ae30
Status affected
Version 8f873cc3f67f2257493063e57d0caf07ef889ee9
Status affected
Version 6.1.72
Version < 6.2
Status affected
Version 6.5.12
Version < 6.6
Status affected
Version 6.6.2
Version < 6.7
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.7
Status affected
Version 0
Version < 6.7
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.049
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/48a0209d8da0d90a7b0a0db19d1ff88027b13781
https://git.kernel.org/stable/c/61aaa8782bec59ecffd22e030f54ef9351bcabf9