7.8
CVE-2026-93148
- EPSS 0.12%
- Veröffentlicht 17.09.2026 16:11:45
- Zuletzt bearbeitet 18.09.2026 18:18:22
- Erkennungen
bpf: Reject MEM_ALLOC BTF accesses past object bounds
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject MEM_ALLOC BTF accesses past object bounds BTF struct walks relax the struct-size check for accesses through a trailing flexible array. That is valid for ordinary BTF type walking, but PTR_TO_BTF_ID | MEM_ALLOC values point to objects allocated with the static BTF type size. When walking a MEM_ALLOC object, reject the access before applying the flexible-array relaxation if the access range extends past the struct size. Apply the same policy to struct ID matching so kfunc and kptr type checks do not walk past the allocated object bounds either.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
958cf2e273f0929c66169e0788031310e8118722
Version <
e626a50d07d43421cbf7bfb5a084b33a5e276b6e
Status
affected
Version
958cf2e273f0929c66169e0788031310e8118722
Version <
9c9ee0324c774490ae953162aaaf4561d222bd93
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.2
Status
affected
Version
0
Version <
6.2
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.021 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/e626a50d07d43421cbf7bfb5a084b33a5e276b6e
https://git.kernel.org/stable/c/9c9ee0324c774490ae953162aaaf4561d222bd93