Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix WARNING in bpf_tracing_link_release

The trampoline could be corrupted by the blindly
'tr->flags = BPF_TRAMP_F_TAIL_CALL_CTX' in verifier.

1. A fexit attached to a tail_call_reachable prog. 'tr->flags' became
'BPF_TRAMP_F_CALL_ORIG | BPF_TRAMP_F_TAIL_CALL_CTX'. And, the
trampoline would poke the target prog's nop insn using jmp insn instead
of call insn.
2. Another fexit loaded with the same tail_call_reachable prog target.
'tr->flags' became 'BPF_TRAMP_F_TAIL_CALL_CTX'.
3. Close the first fexit link. Due to no BPF_TRAMP_F_CALL_ORIG in
'tr->flags', the trampoline will fail to restore the prog's nop insn
using call insn.

[ 3.410719] WARNING: kernel/bpf/syscall.c:3551 at bpf_tracing_link_release+0x53/0x60, CPU#1: test_progs/98
...
[ 3.428793] bpf_link_free+0x58/0x130
[ 3.429293] bpf_link_release+0x23/0x30

Fix the warning by updating 'tr->flags' with '|=' and lock.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel data corruption and potential instability
Action: Patch kernel
AI Analysis

Impact

An internal bug in the Linux kernel’s BPF tracing subsystem incorrectly updates the flags used by the trampoline when a BPF tail‑call program is released. The verifier assigns the flag BPF_TRAMP_F_TAIL_CALL_CTX without accounting for existing flag bits, causing the trampoline to overwrite a target program’s NOP instruction with a JMP instruction or to restore the instruction with the wrong call encoding. This misbehavior can corrupt the target program’s code area and result in kernel instability or a crash.

Affected Systems

All stock Linux kernel releases that ship with BPF tracing support and do not include the patch that was committed in kernel revisions 48a0209d8da0d90a7b0a0db19d1ff88027b13781 and 61aaa8782bec59ecffd22e030f54ef9351bcabf9 are affected. The issue applies to every kernel version prior to the inclusion of these commits.

Risk and Exploitability

The CVSS score of 7.8 classifies the flaw as high severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation at the time of assessment, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local user with the ability to load custom BPF programs, so the attack vector is a privileged local adversary. Successful exploitation could lead to kernel memory corruption, crashes, or other instability, but does not provide a straightforward privilege escalation path.

Generated by OpenCVE AI on September 20, 2026 at 00:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel version that includes the commit 48a0209d8da0d90a7b0a0db19d1ff88027b13781 or the commit 61aaa8782bec59ecffd22e030f54ef9351bcabf9, which contain the patch for bpf_tracing_link_release.
  • If an upgrade cannot be performed immediately, limit or disable the use of BPF tail‑call programs in your environment or configure the kernel to avoid the bpf_tracing_link_release path, if such configuration options exist.
  • Monitor kernel logs for recurring WARNING messages originating from bpf_tracing_link_release and address any occurrences promptly.

Generated by OpenCVE AI on September 20, 2026 at 00:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-362

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665
CWE-787

Sat, 19 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665
CWE-787

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Fix WARNING in bpf_tracing_link_release The trampoline could be corrupted by the blindly 'tr->flags = BPF_TRAMP_F_TAIL_CALL_CTX' in verifier. 1. A fexit attached to a tail_call_reachable prog. 'tr->flags' became 'BPF_TRAMP_F_CALL_ORIG | BPF_TRAMP_F_TAIL_CALL_CTX'. And, the trampoline would poke the target prog's nop insn using jmp insn instead of call insn. 2. Another fexit loaded with the same tail_call_reachable prog target. 'tr->flags' became 'BPF_TRAMP_F_TAIL_CALL_CTX'. 3. Close the first fexit link. Due to no BPF_TRAMP_F_CALL_ORIG in 'tr->flags', the trampoline will fail to restore the prog's nop insn using call insn. [ 3.410719] WARNING: kernel/bpf/syscall.c:3551 at bpf_tracing_link_release+0x53/0x60, CPU#1: test_progs/98 ... [ 3.428793] bpf_link_free+0x58/0x130 [ 3.429293] bpf_link_release+0x23/0x30 Fix the warning by updating 'tr->flags' with '|=' and lock.
Title bpf: Fix WARNING in bpf_tracing_link_release
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:25.436Z

Reserved: 2026-09-16T12:21:13.870Z

Link: CVE-2026-92485

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:50.590

Modified: 2026-09-18T18:18:12.610

Link: CVE-2026-92485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:00:13Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')