Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Disable preemption in bpf_get_stackid

The get_perf_callchain call needs disabled preemption plus we need
it disabled as long as we access its returned trace entries buffer.

Note the bpf_get_stackid_pe function is executed already with
preemption disabled.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Buffer Corruption
Action: Patch Kernel
AI Analysis

Impact

The vulnerability lies in the Linux kernel BPF subsystem’s bpf_get_stackid routine. In the affected code, preemption remains enabled while the routine accesses a stack trace buffer, creating a race condition that can corrupt kernel memory. The advisory notes that a commit has been applied to disable preemption for this path, but it does not detail the exact outcome if the race occurs. The flaw potentially leads to unstable kernel behavior or crashes when the BPF subsystem is used for performance monitoring.

Affected Systems

All Linux kernel installations that have not yet applied the commit disabling preemption in bpf_get_stackid are affected. This includes out‑of‑date kernels across major distributions that rely on the BPF subsystem for tracing or performance analysis.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity if the race can be exercised. The EPSS score of < 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that a local user with the ability to load or execute BPF programs that invoke bpf_get_stackid could trigger the race, potentially leading to kernel buffer corruption or a crash.

Generated by OpenCVE AI on September 18, 2026 at 10:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the commit disabling preemption in bpf_get_stackid
  • Reboot the system to load the updated kernel and reload any BPF programs
  • If a kernel update is not immediately available, disable or avoid using BPF programs that call bpf_get_stackid until the patch is applied

Generated by OpenCVE AI on September 18, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Fri, 18 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Disable preemption in bpf_get_stackid The get_perf_callchain call needs disabled preemption plus we need it disabled as long as we access its returned trace entries buffer. Note the bpf_get_stackid_pe function is executed already with preemption disabled.
Title bpf: Disable preemption in bpf_get_stackid
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:15:04.283Z

Reserved: 2026-09-11T19:38:34.767Z

Link: CVE-2026-89799

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:44.767

Modified: 2026-09-21T14:17:27.000

Link: CVE-2026-89799

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:30:07Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')