-

CVE-2026-98048

bpf: don't rewrite bpf_fastcall patterns entered by a jump

In the Linux kernel, the following vulnerability has been resolved:

bpf: don't rewrite bpf_fastcall patterns entered by a jump

mark_fastcall_pattern_for_call() must ensure that matched
"spill; call; fill" instruction series is not interrupted by a jump.
Otherwise the rewrite applied by bpf_remove_fastcall_spills_fills()
is not sound.

Record the instructions targeted by jumps in
insn_aux_data[*].jump_target when the CFG is built and use this flag
to stop growing a pattern at such an instruction. Jumps to the first
spill are fine.

Note that existing insn_aux_data[*].jmp_point field can't be reused,
as it marks subprogram return instructions.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 5b5f51bff1b66cedb62b5ba74a1878341204e057
Version < 24adbc2c3bbe3385ce922587e1f8e837a68b3e25
Status affected
Version 5b5f51bff1b66cedb62b5ba74a1878341204e057
Version < 0b1c83dc3c4401cd7e846548f62e3caf3d06742e
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.12
Status affected
Version 0
Version < 6.12
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.04
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/24adbc2c3bbe3385ce922587e1f8e837a68b3e25
https://git.kernel.org/stable/c/0b1c83dc3c4401cd7e846548f62e3caf3d06742e