Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix CFI mismatch in task work callback

BPF subprograms use the bpf_callback_t ABI, but task work invokes the
callback through a three-argument function pointer. This trips kCFI.

Store and invoke the callback as bpf_callback_t.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Kernel Crash
Action: Immediate Patch
AI Analysis

Impact

The kernel’s BPF module expects callbacks to match a specific ABI. During task work scheduling, the callback was invoked through a three‑argument function pointer, a mismatch that triggers the kernel’s Control‑Flow Integrity (kCFI) checks. The result is an assertion failure and a kernel panic, effectively shutting down the system. This failure is a classic kernel memory corruption, mapped to CWE‑760.

Affected Systems

All Linux kernel releases preceding the commit that introduced the fix are affected. The vulnerability resides in the generic BPF subsystem and the task work execution path. Vendors that ship unmodified upstream kernels, such as the mainline Linux kernel maintained by the Linux Foundation, are included. No specific vendor product strings or version ranges are listed in the CNA data, so the impact covers every system with an unpatched kernel.

Risk and Exploitability

EPSS is below 1% and the vulnerability is not listed in CISA KEV, indicating a low probability of widespread exploitation. Based on the description, it is inferred that an attacker would need to load a BPF program with appropriate privileges, typically root or a capability such as CAP_SYS_ADMIN. Once the callback is invoked, the kernel crashes, resulting in a denial‑of‑service. The lack of a known public exploit and the local nature of the required privilege mean the risk is moderate but still significant for any systems that allow unrestricted BPF code execution.

Generated by OpenCVE AI on September 19, 2026 at 12:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the CVE-2026-92486 fix.
  • If an immediate kernel upgrade is not feasible, restrict BPF program loading to trusted users or disable BPF support entirely using kernel boot parameters.
  • Enable kernel logging to capture kCFI crashes and monitor for unexpected reboots or panics.

Generated by OpenCVE AI on September 19, 2026 at 12:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-760

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Fix CFI mismatch in task work callback BPF subprograms use the bpf_callback_t ABI, but task work invokes the callback through a three-argument function pointer. This trips kCFI. Store and invoke the callback as bpf_callback_t.
Title bpf: Fix CFI mismatch in task work callback
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:01.654Z

Reserved: 2026-09-16T12:21:13.870Z

Link: CVE-2026-92486

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:50.697

Modified: 2026-09-17T17:17:50.697

Link: CVE-2026-92486

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T12:45:16Z

Weaknesses
  • CWE-760

    Use of a One-Way Hash with a Predictable Salt