Description
In the Linux kernel, the following vulnerability has been resolved:

riscv, bpf: Fix missing sign-ext for signed 1-byte and 2-byte kfunc args

On RV64, the ABI requires sign-extension for signed 1-byte and 2-byte kfunc
args. However, the RV64 JIT currently does not perform sign-extension for
such kfunc args.

Before commit 7ce090afbf72 ("bpf: Infer zext_dst based on static register
liveness analysis"), state pruning could potentially omit zero-extension
of 32-bit subregisters, which inadvertently masked the above issue by making
the args appear as if they had been properly sign-extended. After that
commit, the problem is exposed, causing the kfunc_call/kfunc_call_test4
selftest to fail.

Fix this by extending the existing sign-extension logic to handle signed
1-byte and 2-byte kfunc args as well.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential Privilege Escalation via Incorrect BPF JIT Argument Sign Extension
Action: Apply patch
AI Analysis

Impact

In RV64 Linux kernels, the BPF JIT compiler failed to sign‑extend 1‑byte and 2‑byte signed arguments passed to kernel functions, causing them to be interpreted incorrectly. An attacker who can load crafted BPF code could make kernel functions receive malicious values, potentially leading to unintended execution paths or privilege escalation. The weakness is a type‑conversion flaw, specifically improper conversion or interpretation of data (CWE‑681).

Affected Systems

Linux kernel running on RISC‑V 64‑bit processors (RV64). The issue applies to all kernel releases prior to the commit that added correct sign‑extension; no specific version list is provided, so any unpatched RV64 kernel is potentially vulnerable.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating a low likelihood of exploitation. Exploitation would require the ability to load a BPF program that uses signed one‑ or two‑byte arguments in a kfunc call, suggesting a local or privileged attacker scenario. The CVSS score is not provided, but the lack of exploitation evidence and the specialized attack surface imply a moderate to low overall risk.

Generated by OpenCVE AI on September 19, 2026 at 03:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the sign‑extension fix.
  • If an update cannot be applied immediately, restrict BPF program loading for untrusted users by disabling user‑mode BPF or applying appropriate kernel configuration changes.
  • Audit kernel boot logs and BPF selftest failures to detect potential misuse of kfunc calls.

Generated by OpenCVE AI on September 19, 2026 at 03:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-681

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix missing sign-ext for signed 1-byte and 2-byte kfunc args On RV64, the ABI requires sign-extension for signed 1-byte and 2-byte kfunc args. However, the RV64 JIT currently does not perform sign-extension for such kfunc args. Before commit 7ce090afbf72 ("bpf: Infer zext_dst based on static register liveness analysis"), state pruning could potentially omit zero-extension of 32-bit subregisters, which inadvertently masked the above issue by making the args appear as if they had been properly sign-extended. After that commit, the problem is exposed, causing the kfunc_call/kfunc_call_test4 selftest to fail. Fix this by extending the existing sign-extension logic to handle signed 1-byte and 2-byte kfunc args as well.
Title riscv, bpf: Fix missing sign-ext for signed 1-byte and 2-byte kfunc args
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:14.979Z

Reserved: 2026-09-11T19:38:34.792Z

Link: CVE-2026-90195

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:14.280

Modified: 2026-09-17T17:17:14.280

Link: CVE-2026-90195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:30:18Z

Weaknesses
  • CWE-681

    Incorrect Conversion between Numeric Types