Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Check load-acquire src ptr type before the load

check_atomic_load() calls check_load_mem() before atomic_ptr_type_ok().
For a load-acquire that fetches into its own source register (dst_reg ==
src_reg), check_load_mem() overwrites src_reg's type with the type of the
loaded value, so the subsequent atomic_ptr_type_ok() no longer sees the
source pointer and fails to reject the disallowed types (ctx, pkt,
flow_keys, sock).

Since bpf_convert_ctx_accesses() does not rewrite atomic loads, the raw
access to the underlying kernel object is left in place. The destination
type is taken from the ctx access itself, so a load-acquire of the sk
field of struct __sk_buff for example leaves the register typed as
PTR_TO_SOCK_COMMON_OR_NULL, which type_is_sk_pointer() does not match
either, while it actually holds unconverted struct sk_buff bytes. Once
the NULL check has passed this is a type confusion, not just a leak of
kernel data.

Validate src_reg with check_reg_arg() and check the source pointer type
with atomic_ptr_type_ok() before the load again, mirroring
check_atomic_rmw(). Out-of-range register numbers are already rejected
earlier by check_and_resolve_insns() (commit 503d21ef8eac ("bpf: Do
register range validation early")), and the only exemption there,
is_stack_arg_ldx(), requires BPF_LDX | BPF_MEM | BPF_DW and thus never
matches a BPF_ATOMIC insn. atomic_ptr_type_ok() can therefore not
dereference register state out of bounds, that is, the out-of-bounds
read addressed by the Fixes commit below does not reappear (as proven
also via selftest).
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel type confusion potentially allowing privilege escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a type‑confusion flaw in the Linux kernel BPF virtual machine. During a load‑acquire instruction that writes back into the source register, the verifier incorrectly overwrites the register’s type, bypassing a pointer‑type check. As a result a malicious BPF program can load kernel data through an unvalidated pointer, enabling arbitrary reads of kernel memory and potentially privilege escalation.

Affected Systems

It affects all kernel releases that include the buggy commit 422a416041172af1ac610736d5f556d22b31b115 and its successors. The flaw resides in the eBPF subsystem used by tools such as bpftool, networking packet filters, and other kernel components that load eBPF programs. Users running older kernel releases should verify whether the fix has been incorporated and plan an upgrade if it is absent.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1 % signals a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the likely attack vector is the injection or execution of crafted BPF bytecode through a privileged interface such as bpftool or a kernel socket; once the verifier accepts the code, the type‑confusion allows an unrestricted read of kernel memory.

Generated by OpenCVE AI on September 20, 2026 at 03:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that incorporates commit 422a416041172af1ac610736d5f556d22b31b115 or later to apply the official fix.
  • If a kernel update is not immediately feasible, restrict eBPF program loading to unprivileged users or disable the load‑acquire instruction by configuring the verifier to reject such instructions.
  • Monitor kernel logs for BPF verifier errors and audit active eBPF programs for suspicious load‑acquire operations.

Generated by OpenCVE AI on September 20, 2026 at 03:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-704

Sun, 20 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Sat, 19 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Check load-acquire src ptr type before the load check_atomic_load() calls check_load_mem() before atomic_ptr_type_ok(). For a load-acquire that fetches into its own source register (dst_reg == src_reg), check_load_mem() overwrites src_reg's type with the type of the loaded value, so the subsequent atomic_ptr_type_ok() no longer sees the source pointer and fails to reject the disallowed types (ctx, pkt, flow_keys, sock). Since bpf_convert_ctx_accesses() does not rewrite atomic loads, the raw access to the underlying kernel object is left in place. The destination type is taken from the ctx access itself, so a load-acquire of the sk field of struct __sk_buff for example leaves the register typed as PTR_TO_SOCK_COMMON_OR_NULL, which type_is_sk_pointer() does not match either, while it actually holds unconverted struct sk_buff bytes. Once the NULL check has passed this is a type confusion, not just a leak of kernel data. Validate src_reg with check_reg_arg() and check the source pointer type with atomic_ptr_type_ok() before the load again, mirroring check_atomic_rmw(). Out-of-range register numbers are already rejected earlier by check_and_resolve_insns() (commit 503d21ef8eac ("bpf: Do register range validation early")), and the only exemption there, is_stack_arg_ldx(), requires BPF_LDX | BPF_MEM | BPF_DW and thus never matches a BPF_ATOMIC insn. atomic_ptr_type_ok() can therefore not dereference register state out of bounds, that is, the out-of-bounds read addressed by the Fixes commit below does not reappear (as proven also via selftest).
Title bpf: Check load-acquire src ptr type before the load
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:29.867Z

Reserved: 2026-09-11T19:38:34.801Z

Link: CVE-2026-90312

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:28.977

Modified: 2026-09-18T18:17:53.130

Link: CVE-2026-90312

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:30:13Z

Weaknesses
  • CWE-704

    Incorrect Type Conversion or Cast