-

CVE-2026-98151

bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic

Take the following unprivileged program as an example:

	r0 = bpf_map_lookup_elem(...)	/* PTR_TO_MAP_VALUE, offset 0 */
	...
	14: r0 += r1			/* r1 is a bounded scalar */
	15: r9 = r0

Loading it triggers a verifier warning from reg_bounds_sanity_check():

	verifier bug: REG INVARIANTS VIOLATION (alu): const subreg tnum out
	of sync with range bounds r64={.base=0x0, .size=0x0}
	r32={.base=0x0, .size=0xffffffff} var_off=(0x0, 0x0)

What happens:

1. Processing insn 14 (r0 += r1) in adjust_ptr_min_max_vals(), the new
   offset is computed into dst_reg's var_off and 32/64-bit ranges.

2. Because pointer registers do not track 32-bit subregister bounds,
   __mark_reg32_unbounded() first sets r32 to the full range; r32 is
   re-derived from the offset at the end of the function by
   reg_bounds_sync().

3. On the unprivileged path, sanitize_ptr_alu() is called and, via
   sanitize_speculative_path() -> push_stack(), snapshots the current
   register state and schedules the next instruction (insn 15) to be
   verified directly as a speculative path.

4. That snapshot is taken between step 2 and the final reg_bounds_sync():
   at this point dst_reg's var_off still holds the (const) original
   offset while r32 has just been blanked to the full range, i.e. the two
   are out of sync. When the speculative path later verifies insn 15
   (r9 = r0), the inconsistent state reaches reg_bounds_sanity_check() and
   trips the warning.

var_off and the 32-bit range must always be consistent. There are two
ways to keep the snapshot consistent:

  1. sync var_off and r32 before the snapshot so they match, or
  2. leave r32 at its original (already consistent) value and blank it
     only after the snapshot.

The whole point of sanitize_ptr_alu() is to insert a harmless masking
sequence that keeps the access in bounds under speculation, so the state
it snapshots should faithfully represent that. Take approach 2: move
__mark_reg32_unbounded() to after sanitize_ptr_alu(), so the speculative
snapshot keeps the pointer's original, consistent r32. The non-speculative
path is unchanged: r32 is still blanked before the offset is applied and
re-derived by reg_bounds_sync().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 5f99f312bd3bedb3b266b0d26376a8c500cdc97f
Version < 21a681526c715aebb4f918b8c131583442d1b3d8
Status affected
Version 5f99f312bd3bedb3b266b0d26376a8c500cdc97f
Version < d623a4a58bb238443505d5c2949d1182dcfc26b6
Status affected
Version 5f99f312bd3bedb3b266b0d26376a8c500cdc97f
Version < 9f9477ae73de9c5a28e8ab7000d8097b078faee4
Status affected
Version 5f99f312bd3bedb3b266b0d26376a8c500cdc97f
Version < 150aeba624e8b7cac51c39440d7e8e1fd11de9a0
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.8
Status affected
Version 0
Version < 6.8
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.041
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/21a681526c715aebb4f918b8c131583442d1b3d8
https://git.kernel.org/stable/c/d623a4a58bb238443505d5c2949d1182dcfc26b6
https://git.kernel.org/stable/c/9f9477ae73de9c5a28e8ab7000d8097b078faee4
https://git.kernel.org/stable/c/150aeba624e8b7cac51c39440d7e8e1fd11de9a0