Description
In the Linux kernel, the following vulnerability has been resolved:

bpf, s390: Clear fetch destination on faulting arena atomic

Same missing register clear as on riscv64. A RMW atomic on an arena pointer
is converted to BPF_PROBE_ATOMIC and gets an exception table entry, but
bpf_jit_probe_atomic_pre() only fills in the arena base and the probe
offset, leaving probe->reg at the -1 that bpf_jit_probe_init() set, which
bpf_jit_probe_post() writes into the entry and ex_handler_bpf() then reads
back as "there is nothing to clear".

That is right for a plain BPF_{ADD,AND,OR,XOR}, which only writes memory,
but an RMW carrying BPF_FETCH also reads the old value into a register:
src_reg for BPF_{ADD,AND,OR,XOR} | BPF_FETCH and BPF_XCHG, and r0 for
BPF_CMPXCHG. So on a fault over an unmapped arena page the program resumes
at the landing pad with whatever that register held before the atomic
instead of the 0 that every other BPF_PROBE_* access delivers.

Fill probe->reg in from bpf_atomic_load_reg(). Unlike x86-64 and arm64,
s390x does not report arena violations from its exception handler, so there
is no access direction to correct here, only the missing register clear.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Incorrect register clearing leading to potential data leakage or BPF execution errors
Action: Apply patch
AI Analysis

Impact

The vulnerability resides in the Linux kernel’s BPF subsystem on the s390 architecture. A missing register clear occurs when a read‑modify‑write (RMW) atomic operation that performs a fetch faults over an unmapped arena page. The exception handler writes into the probe entry but leaves the register that should hold the fetched value unchanged; it retains whatever stale data was in that register before the atomic operation. This flaw means that a BPF program could observe or propagate arbitrary register contents instead of the expected zero or fresh data, which could lead to incorrect BPF execution or, if the stale data contains sensitive information, unintended data leakage. The weakness corresponds to improper initialization of a register (CWE‑665).

Affected Systems

Affected systems are Linux kernel deployments compiled for the s390 (s390x) platform that have not yet incorporated the patch referenced in the commits linked above. Since the patch removes the register‑clear bug, any kernel revision prior to the commit that introduced the fix is considered vulnerable. No specific vendor product versions were listed, so the risk applies to all s390 Linux kernels before the patch.

Risk and Exploitability

The EPSS score for this vulnerability is reported as less than 1 %, indicating a very low estimated likelihood of exploitation in the current environment. The vulnerability is not listed in CISA’s KEV catalog. It is inferred from the description that exploitation requires the ability to load or compile BPF programs that perform atomic fetch operations; therefore, a local attacker with sufficient privileges or capabilities would be needed to trigger the fault path. No public exploits are known. Given the low EPSS score and the privilege requirements, the overall risk is assessed as low, but it could be higher in environments with permissive BPF loading policies.

Generated by OpenCVE AI on September 20, 2026 at 03:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the register clear fix for s390 atomics, as provided in the official kernel updates.
  • If an update cannot be applied immediately, restrict BPF program loading to the minimum set of trusted users or capabilities, and enforce SELinux/AppArmor policies that limit the use of atomic fetch operations in user‑supplied BPF code.
  • Enforce stricter BPF program loading policies by rejecting programs that contain atomic fetch operations, ensuring only verified and trusted BPF code is allowed to execute.

Generated by OpenCVE AI on September 20, 2026 at 03:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 14:30:00 +0000


Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf, s390: Clear fetch destination on faulting arena atomic Same missing register clear as on riscv64. A RMW atomic on an arena pointer is converted to BPF_PROBE_ATOMIC and gets an exception table entry, but bpf_jit_probe_atomic_pre() only fills in the arena base and the probe offset, leaving probe->reg at the -1 that bpf_jit_probe_init() set, which bpf_jit_probe_post() writes into the entry and ex_handler_bpf() then reads back as "there is nothing to clear". That is right for a plain BPF_{ADD,AND,OR,XOR}, which only writes memory, but an RMW carrying BPF_FETCH also reads the old value into a register: src_reg for BPF_{ADD,AND,OR,XOR} | BPF_FETCH and BPF_XCHG, and r0 for BPF_CMPXCHG. So on a fault over an unmapped arena page the program resumes at the landing pad with whatever that register held before the atomic instead of the 0 that every other BPF_PROBE_* access delivers. Fill probe->reg in from bpf_atomic_load_reg(). Unlike x86-64 and arm64, s390x does not report arena violations from its exception handler, so there is no access direction to correct here, only the missing register clear.
Title bpf, s390: Clear fetch destination on faulting arena atomic
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:15:21.625Z

Reserved: 2026-09-11T19:38:34.793Z

Link: CVE-2026-90211

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:16.330

Modified: 2026-09-21T14:17:28.800

Link: CVE-2026-90211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:15:08Z

Weaknesses