7.8

CVE-2026-93138

bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux

bpf_get_btf_vmlinux() lazily parses the vmlinux BTF under the
bpf_verifier_lock, but publishes the result through a plain store
and re-checks it through a plain lockless load. Nothing orders
the stores initializing the struct btf inside btf_parse_vmlinux()
against the store publishing the pointer: On a weakly ordered
arch, a concurrent first-time caller taking the lockless fast
path could in principle observe the pointer before the parsed
contents are visible. The mutex_unlock() does not help such a
reader given it only synchronizes with a later acquisition of the
same lock. Thus, publish the pointer with smp_store_release()
and read it on the fast path with smp_load_acquire().

Acquire semantics are needed rather than a dependency-ordered
READ_ONCE(): btf_parse_vmlinux() also populates globals outside
the returned object (e.g. bpf_ctx_convert.t). An address
dependency would only order accesses performed through the
pointer and not cover other globals.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 8580ac9404f6240668a026785d7d8856f0530409
Version < f32a4a40bc635be25d6816da4bd91e9e58c31bf3
Status affected
Version 8580ac9404f6240668a026785d7d8856f0530409
Version < a7fe72d780122eb934536f1719abad445f6afdf7
Status affected
Version 8580ac9404f6240668a026785d7d8856f0530409
Version < e18a10b39c994f04e1ebd7f8fc042bb1ca8ad053
Status affected
Version 8580ac9404f6240668a026785d7d8856f0530409
Version < 978524ecfc1c539282df5858de1eec20748c6f74
Status affected
Version 8580ac9404f6240668a026785d7d8856f0530409
Version < eaf302628a78806f66d8224d6ba03fb4d5025de4
Status affected
Version 8580ac9404f6240668a026785d7d8856f0530409
Version < 2892f3f44bf865c8fb6b6c0960edec4cc91806ee
Status affected
Version 8580ac9404f6240668a026785d7d8856f0530409
Version < 86d11c594d60b255b526fa5260f669463fb1a063
Status affected
Version 8580ac9404f6240668a026785d7d8856f0530409
Version < 92863e678070f57c17c868e4bfa2441a5c61ad2b
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.5
Status affected
Version 0
Version < 5.5
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.074
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f32a4a40bc635be25d6816da4bd91e9e58c31bf3
https://git.kernel.org/stable/c/a7fe72d780122eb934536f1719abad445f6afdf7
https://git.kernel.org/stable/c/e18a10b39c994f04e1ebd7f8fc042bb1ca8ad053
https://git.kernel.org/stable/c/978524ecfc1c539282df5858de1eec20748c6f74
https://git.kernel.org/stable/c/eaf302628a78806f66d8224d6ba03fb4d5025de4
https://git.kernel.org/stable/c/2892f3f44bf865c8fb6b6c0960edec4cc91806ee
https://git.kernel.org/stable/c/86d11c594d60b255b526fa5260f669463fb1a063
https://git.kernel.org/stable/c/92863e678070f57c17c868e4bfa2441a5c61ad2b