Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Preserve unique-field state across nested structs

btf_find_struct_field() initializes a fresh seen mask for every recursive
descent. Unique special fields in different levels of the same aggregate
therefore do not see one another. The duplicate fields can reach
btf_parse_fields(), where they trigger an invariant WARN_ON_ONCE(). A
crafted user BTF can consequently trigger the warning before map creation
checks capabilities.

Initialize the seen mask once in btf_find_field() and pass the same pointer
through struct, datasec, and nested-struct walks. This gives the entire field
traversal one shared uniqueness state.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Possible unauthorized BPF map creation or denial of service
Action: Assess and Patch
AI Analysis

Impact

A flaw in the Linux kernel’s BPF type‑facing system causes duplicate field identifiers in nested structures to be misidentified as unique during recursive searches. This oversight allows a crafted BPF type format to trigger an invariant warning before the kernel verifies user capabilities when creating a map, potentially bypassing security checks or leading to a kernel warning that could impact stability.

Affected Systems

All Linux kernel versions that include the underscored bug in the bpf subsystem are affected. No specific releases are listed in the data; the issue existed prior to the patch that modified btf_find_field to propagate the seen mask across recursion.

Risk and Exploitability

The EPSS score indicates a very low exploitation probability, and the vulnerability is not in CISA’s KEV catalog. However, an attacker could supply a malicious BTF definition through a user process, exploiting the lack of uniqueness tracking to either gain unauthorized map creation privileges or provoke a kernel warning path that may be used for denial of service. The attack would require the ability to load custom BPF programs and absence of mitigations that reject invalid BTF data.

Generated by OpenCVE AI on September 19, 2026 at 06:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that incorporates the fix to initialize the seen mask once in btf_find_field
  • Reboot the system to load the corrected kernel
  • Disable or tightly restrict loading of BPF programs that use nested structures until the kernel update is deployed

Generated by OpenCVE AI on September 19, 2026 at 06:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve unique-field state across nested structs btf_find_struct_field() initializes a fresh seen mask for every recursive descent. Unique special fields in different levels of the same aggregate therefore do not see one another. The duplicate fields can reach btf_parse_fields(), where they trigger an invariant WARN_ON_ONCE(). A crafted user BTF can consequently trigger the warning before map creation checks capabilities. Initialize the seen mask once in btf_find_field() and pass the same pointer through struct, datasec, and nested-struct walks. This gives the entire field traversal one shared uniqueness state.
Title bpf: Preserve unique-field state across nested structs
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:24.159Z

Reserved: 2026-09-16T12:21:13.873Z

Link: CVE-2026-92515

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:54.360

Modified: 2026-09-17T17:17:54.360

Link: CVE-2026-92515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:30:07Z

Weaknesses