Description
In the Linux kernel, the following vulnerability has been resolved:

bpf, x86: Fix trampoline stack size for 128-bit arguments

btf_distill_func_proto() accepts a function argument up to 16 bytes, so a
128-bit scalar such as __int128 reaches the x86 trampoline with
arg_size == 16. But the current implementation assumes an __int128
argument only needs one register, so the register save area is
under-allocated and save_args() overwrites adjacent stack slots.

Compute the register count from arg_size for all arguments to fix it.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch Kernel
AI Analysis

Impact

The Linux kernel contains a vulnerability in the BPF trampoline handling for 128‑bit arguments. The function that prepares stack frames for BPF calls assumes a 128‑bit scalar needs only one register, causing the register save area to be under‑allocated. When a 128‑bit argument is passed, the save_args routine writes beyond the allocated stack region, corrupting adjacent stack slots. This stack‑based buffer overflow can potentially lead to arbitrary code execution or a kernel panic, compromising system confidentiality, integrity, or availability. The weakness stems from improper calculation of stack space and is an instance of a stack‑based buffer overflow (CWE‑121).

Affected Systems

The flaw resides in the Linux kernel’s BPF subsystem. The affected products are Linux kernel builds that include the BPF component, but specific version ranges are not provided—the fix applies to any kernel containing the uncorrected stack size logic. Administrators should review the kernel release notes for versions containing the relevant commits.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1% implies that exploitation is unlikely at present. The vulnerability is not yet listed in the CISA KEV catalog. Attackers would need the ability to load or influence BPF programs, typically requiring privileged or local access, to exploit the stack corruption. Given the low probability and the need for local system access, the risk is moderate but warrants remediation.

Generated by OpenCVE AI on September 19, 2026 at 15:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the fix (e.g., the commit referenced in the advisory).
  • If a kernel update cannot be applied immediately, restrict BPF program loading to users with the appropriate capabilities and consider disabling BPF features that are not required.
  • Monitor system logs for BPF‑related panics or segmentation faults and apply standard kernel hardening practices, including enabling address space layout randomization (ASLR) and stack protection.

Generated by OpenCVE AI on September 19, 2026 at 15:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf, x86: Fix trampoline stack size for 128-bit arguments btf_distill_func_proto() accepts a function argument up to 16 bytes, so a 128-bit scalar such as __int128 reaches the x86 trampoline with arg_size == 16. But the current implementation assumes an __int128 argument only needs one register, so the register save area is under-allocated and save_args() overwrites adjacent stack slots. Compute the register count from arg_size for all arguments to fix it.
Title bpf, x86: Fix trampoline stack size for 128-bit arguments
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:50.685Z

Reserved: 2026-09-11T19:38:34.806Z

Link: CVE-2026-90358

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:34.703

Modified: 2026-09-18T18:17:55.317

Link: CVE-2026-90358

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:45:16Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow