Description
In the Linux kernel, the following vulnerability has been resolved:

LoongArch: BPF: Move arena register slot below TCC context

Currently, the stack layout places the optional arena register slot
above the tail call counter context. When arena_vm_start is dynamically
enabled, it shifts the relative offset of the tcc_ptr slot within the
stack frame, causing hardcoded tracking macros to mismatch and leading
to memory misalignment or corruption potentially.

To fix this, move the arena register save and restore sequences below
the tail call counter context slots in both build_prologue() and the
epilogue.

Update __build_epilogue() to insert a proper offset decrement to safely
skip the unneeded tcc_ptr reading block while accurately aligning with
the relocated arena slot at the very bottom.

With this patch, the tcc_ptr slot is always positioned at a fixed
distance directly underneath the base callee-saved registers that is
independent of whether the arena features are on.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption
Action: Apply Patch
AI Analysis

Impact

The vulnerability is located in the LoongArch BPF implementation of the Linux kernel, where the stack layout incorrectly places the optional arena register slot above the tail call counter (tcc) context. When the arena_vm_start feature is enabled, this placement shifts the relative offset of the tcc_ptr slot, causing hardcoded tracking macros to no longer match the actual layout. The resulting misalignment can lead to memory corruption, including misaligned or overwritten data on the stack.

Affected Systems

This bug affects any instance of the Linux kernel running on LoongArch processors that includes the BPF stack layout with the arena register slot above the tcc context. No specific kernel versions are listed, but the issue applies wherever the arena_vm_start feature is enabled and the stack frame follows the described layout.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. The attack vector is inferred to be local, requiring execution of malicious BPF programs with the arena_vm_start feature enabled. Because the bug causes memory corruption, a successful exploit could result in kernel stability problems or denial of service, but the absence of known exploits and the low EPSS suggest a moderate immediate risk that can be mitigated by applying the available kernel patch.

Generated by OpenCVE AI on September 18, 2026 at 07:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Implement the kernel patch that moves the arena register slot below the TCC context, or update to a kernel release that incorporates this fix.
  • Recompile any custom BPF programs against the updated kernel to ensure they reference the corrected stack layout.
  • Run BPF verification tools or review kernel logs to confirm proper alignment of the stack frame after the patch.

Generated by OpenCVE AI on September 18, 2026 at 07:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Move arena register slot below TCC context Currently, the stack layout places the optional arena register slot above the tail call counter context. When arena_vm_start is dynamically enabled, it shifts the relative offset of the tcc_ptr slot within the stack frame, causing hardcoded tracking macros to mismatch and leading to memory misalignment or corruption potentially. To fix this, move the arena register save and restore sequences below the tail call counter context slots in both build_prologue() and the epilogue. Update __build_epilogue() to insert a proper offset decrement to safely skip the unneeded tcc_ptr reading block while accurately aligning with the relocated arena slot at the very bottom. With this patch, the tcc_ptr slot is always positioned at a fixed distance directly underneath the base callee-saved registers that is independent of whether the arena features are on.
Title LoongArch: BPF: Move arena register slot below TCC context
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:04.470Z

Reserved: 2026-09-11T19:38:34.774Z

Link: CVE-2026-89905

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:59.483

Modified: 2026-09-16T11:16:59.483

Link: CVE-2026-89905

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:45:06Z

Weaknesses