7.8
CVE-2026-93144
- EPSS 0.18%
- Veröffentlicht 17.09.2026 16:11:42
- Zuletzt bearbeitet 18.09.2026 18:18:22
- Erkennungen
bpf: Reject writes through untrusted BTF pointers
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject writes through untrusted BTF pointers check_ptr_to_btf_access() lets program-type btf_struct_access callbacks validate writes before the default BTF access path rejects non-read accesses. That bypasses the read-only policy for untrusted BTF pointers created by helpers such as bpf_rdonly_cast(). Reject non-read accesses through PTR_UNTRUSTED BTF pointers at the common entry point, before the callback branch to handle all cases.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
282de143ead96a5d53331e946f31c977b4610a74
Version <
19d5566b84ca1af0256d0d0003e1a081580c3ba3
Status
affected
Version
282de143ead96a5d53331e946f31c977b4610a74
Version <
ac65c710cc643cbc52b899627577357867249530
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.2
Status
affected
Version
0
Version <
6.2
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.073 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/19d5566b84ca1af0256d0d0003e1a081580c3ba3
https://git.kernel.org/stable/c/ac65c710cc643cbc52b899627577357867249530