Description
In the Linux kernel, the following vulnerability has been resolved:

LoongArch: BPF: Refactor jump offset calculation in tail call

The old macro-based jmp_offset calculation derives the jump distance
from a stale prior-pass code stride, which can lead to wrong branch
offsets and soft lockups under extra JIT passes.

Fix this by calculating the offset directly on the absolute target:
"ctx->offset[insn + 1] - ctx->idx".

To avoid a false 16-bit range check abort during size estimation, add
a "ctx->image == NULL" guard to inject a safe dummy offset.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via soft lockups
Action: Patch
AI Analysis

Impact

A flaw in the Linux kernel’s BPF interpreter for the LoongArch architecture incorrectly calculates jump offsets during JIT compilation. The legacy jmp_offset macro derived the distance from stale data, leading to wrong branch targets. When these erroneous branches are executed, the kernel can enter a soft‑lockup state, halting normal operation and causing a denial of service. The vulnerability is an arithmetic or calculation error that introduces an improper control flow.

Affected Systems

The issue arises in any Linux kernel build that includes the LoongArch BPF code path. No specific kernel release version was supplied, so any active kernel on a LoongArch system that has not incorporated the recent patch will be vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity impact. The EPSS score of <1% suggests that exploitation attempts are currently rare and the public exposure is limited. The vulnerability is not listed in the CISA KEV catalog, indicating it is not widely exploited in production environments. Attackers would need to supply a crafted BPF program that exercises the flawed JIT path, which is inferred to require local access or an entry point that allows user‑supplied BPF scripts such as via netfilter or eBPF sockets. Without broader public exploitation, the primary risk remains the stability impact on systems that run LoongArch‑targeted kernels.

Generated by OpenCVE AI on September 18, 2026 at 07:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fix for the jmp_offset calculation in the LoongArch BPF code path
  • If an immediate kernel upgrade is not possible, disable BPF JIT compilation for LoongArch systems to avoid the faulty branch logic
  • Monitor system logs for soft lockup indicators and apply the fix or switch to a non‑LoongArch environment as a temporary safeguard

Generated by OpenCVE AI on September 18, 2026 at 07:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Refactor jump offset calculation in tail call The old macro-based jmp_offset calculation derives the jump distance from a stale prior-pass code stride, which can lead to wrong branch offsets and soft lockups under extra JIT passes. Fix this by calculating the offset directly on the absolute target: "ctx->offset[insn + 1] - ctx->idx". To avoid a false 16-bit range check abort during size estimation, add a "ctx->image == NULL" guard to inject a safe dummy offset.
Title LoongArch: BPF: Refactor jump offset calculation in tail call
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:55.665Z

Reserved: 2026-09-11T19:38:34.774Z

Link: CVE-2026-89906

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:59.590

Modified: 2026-09-16T15:18:16.683

Link: CVE-2026-89906

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:30:16Z

Weaknesses