Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject >8 byte return values on return-reading trampoline paths

btf_distill_func_proto() builds the function model used for the
fentry/fexit/fmod_ret/fsession trampolines and struct_ops. It has
accepted a 16-byte __int128 return value since the trampoline was
introduced: __get_type_size() returns the integer's type size, and the
return-type check only rejected ret < 0.

But the BPF trampoline preserves only 8 bytes of the return value (RAX on
x86, i.e. R0). For an attach type that reads the target's return value the
second half (RDX / R3) is neither saved nor restored, so a program
attached to a function returning a 16-byte value corrupts the value seen
by the real caller and itself observes only half of it. struct_ops
trampolines have the same limitation.

This affects the attach types that read the target's return value: fexit,
fmod_ret and fsession (plus the _multi variants of fexit and fsession),
and struct_ops. fentry/fentry_multi run before the target returns and are
unaffected.

Reject a >8 byte return value for these attach types in
bpf_check_attach_target() and bpf_check_attach_btf_id_multi(), and for
struct_ops in bpf_struct_ops_desc_init().
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Return Value Truncation (Data Corruption)
Action: Patch Kernel
AI Analysis

Impact

A recent kernel fix addresses an issue where BPF programs that attach to fexit, fmod_ret, fsession or struct_ops could receive only the lower 8 bytes of a 16‑byte return value. The original trampoline preserved only the low half of the result, while the upper half was discarded, causing the attached BPF program and the real caller to see a corrupted value. This truncation can lead to incorrect program behaviour and potential data integrity problems within kernel space.

Affected Systems

The vulnerability impacts all Linux distributions running a kernel version that includes the buggy return‑reading trampoline behaviour. There is no specific product or version list supplied, but it applies to any kernel where BPF attach types fexit, fmod_ret, fsession (and the _multi variants) or struct_ops were employed before the patch.

Risk and Exploitability

The EPSS score is reported as < 1%, indicating a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalogue. The CVSS score is not provided, so severity inference is limited. Based on the description, the attack vector is likely a malicious BPF program that makes a >8byte return and is attached via a return‑reading type; the program would then observe a truncated value, potentially leading to subtle kernel inconsistencies. No privileged escalation is explicitly described, but the data corruption could be leveraged in a complex attack chain if the impacted value influences critical logic.

Generated by OpenCVE AI on September 19, 2026 at 05:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the patch rejecting return values larger than 8 bytes for return‑reading trampoline attach types.
  • Review any BPF programs that attach with fexit, fmod_ret, fsession, or struct_ops and ensure they return 8 bytes or fewer; modify or remove programs that violate this rule.
  • If an immediate kernel upgrade is infeasible, temporarily restrict or disable the affected BPF attach types in the environment to prevent the use of programs that could return oversized values.

Generated by OpenCVE AI on September 19, 2026 at 05:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-681

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Reject >8 byte return values on return-reading trampoline paths btf_distill_func_proto() builds the function model used for the fentry/fexit/fmod_ret/fsession trampolines and struct_ops. It has accepted a 16-byte __int128 return value since the trampoline was introduced: __get_type_size() returns the integer's type size, and the return-type check only rejected ret < 0. But the BPF trampoline preserves only 8 bytes of the return value (RAX on x86, i.e. R0). For an attach type that reads the target's return value the second half (RDX / R3) is neither saved nor restored, so a program attached to a function returning a 16-byte value corrupts the value seen by the real caller and itself observes only half of it. struct_ops trampolines have the same limitation. This affects the attach types that read the target's return value: fexit, fmod_ret and fsession (plus the _multi variants of fexit and fsession), and struct_ops. fentry/fentry_multi run before the target returns and are unaffected. Reject a >8 byte return value for these attach types in bpf_check_attach_target() and bpf_check_attach_btf_id_multi(), and for struct_ops in bpf_struct_ops_desc_init().
Title bpf: Reject >8 byte return values on return-reading trampoline paths
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:04.187Z

Reserved: 2026-09-11T19:38:34.806Z

Link: CVE-2026-90359

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:34.810

Modified: 2026-09-17T17:17:34.810

Link: CVE-2026-90359

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T06:30:16Z

Weaknesses
  • CWE-681

    Incorrect Conversion between Numeric Types