-

CVE-2026-97420

bpf: NUL-terminate replaced sysctl value

In the Linux kernel, the following vulnerability has been resolved:

bpf: NUL-terminate replaced sysctl value

When writing to sysctls, proc_sys_call_handler() guarantees that the
buffer passed to proc handlers is NUL-terminated. If
bpf_sysctl_set_new_value() replaces the pending sysctl value, it can
hand a replacement buffer directly to proc handlers. However, the
helper currently copies only buf_len bytes into that buffer without
appending a NUL terminator, leaving downstream parsers vulnerable to
out-of-bounds access.

Fix this by appending a '\0' after the replaced value to restore the
expected sysctl semantics. Since the helper already rejects buf_len
greater than PAGE_SIZE - 1, there is always room for the extra byte.

Reproduced in a QEMU x86_64 guest booted with KASAN while exercising
the sysctl replacement path with a cgroup/sysctl BPF program. The
reproducer targets `/proc/sys/net/core/flow_limit_cpu_bitmap`, fills
the original user write buffer with non-zero bytes, and overrides the
sysctl value so the replacement buffer lacks a terminating NUL. Under
that setup, the pre-fix kernel reported:

  BUG: KASAN: slab-out-of-bounds in strnchrnul+0x72/0x90
  Read of size 1 at addr ffff88800de57000 by task repro_patch3/66
  CPU: 0 UID: 0 PID: 66 Comm: repro_patch3 Not tainted 7.1.0-rc3-00269-g8370ca1f87cc #6 PREEMPT(lazy)
  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
  Call Trace:
   <TASK>
   dump_stack_lvl+0x68/0xa0
   print_report+0xcb/0x5e0
   ? __virt_addr_valid+0x21d/0x3f0
   ? strnchrnul+0x72/0x90
   ? strnchrnul+0x72/0x90
   kasan_report+0xca/0x100
   ? strnchrnul+0x72/0x90
   strnchrnul+0x72/0x90
   bitmap_parse+0x37/0x2e0
   flow_limit_cpu_sysctl+0xc6/0x840
   ? __pfx_flow_limit_cpu_sysctl+0x10/0x10
   ? __kvmalloc_node_noprof+0x5ba/0x870
   proc_sys_call_handler+0x31d/0x480
   ? __pfx_proc_sys_call_handler+0x10/0x10
   ? selinux_file_permission+0x39f/0x500
   ? lock_is_held_type+0x9e/0x120
   vfs_write+0x98e/0x1000
   ...
   </TASK>
  The buggy address is located 0 bytes to the right of
  allocated 4096-byte region [ffff88800de56000, ffff88800de57000)
With this fix applied, rerunning the same sysctl-targeted path yields
no corresponding KASAN reports.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 32927393dc1ccd60fb2bdc05b9e8e88753761469
Version < bfcee1f79aaefa90679ad47690107fb7682724ec
Status affected
Version 32927393dc1ccd60fb2bdc05b9e8e88753761469
Version < c73e4a04eedc677fe91a736d7a5db45100adba5e
Status affected
Version 32927393dc1ccd60fb2bdc05b9e8e88753761469
Version < 36d3e9f62dc2beb9299d3bb6f589cb9e07f773fe
Status affected
Version 32927393dc1ccd60fb2bdc05b9e8e88753761469
Version < 31377675c3d75603d957c08e338a9ac27e9f6cd5
Status affected
Version 32927393dc1ccd60fb2bdc05b9e8e88753761469
Version < 76c14b10f50eb0afcc76e244562fa2d8c661e224
Status affected
Version 32927393dc1ccd60fb2bdc05b9e8e88753761469
Version < 3b2814dd842a565fcf9cc370156e1ba9eae16239
Status affected
Version 32927393dc1ccd60fb2bdc05b9e8e88753761469
Version < a66e3b5bacf38d6ab29fa05a9754f7a114485605
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.8
Status affected
Version 0
Version < 5.8
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/76c14b10f50eb0afcc76e244562fa2d8c661e224
https://git.kernel.org/stable/c/3b2814dd842a565fcf9cc370156e1ba9eae16239
https://git.kernel.org/stable/c/a66e3b5bacf38d6ab29fa05a9754f7a114485605
https://git.kernel.org/stable/c/31377675c3d75603d957c08e338a9ac27e9f6cd5
https://git.kernel.org/stable/c/36d3e9f62dc2beb9299d3bb6f589cb9e07f773fe
https://git.kernel.org/stable/c/bfcee1f79aaefa90679ad47690107fb7682724ec
https://git.kernel.org/stable/c/c73e4a04eedc677fe91a736d7a5db45100adba5e