Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix offset warn check for bpf_res_spin_lock

Sashiko pointed out correctly that the case statement for
BPF_RES_SPIN_LOCK incorrectly checks offset for BPF_SPIN_LOCK.
Fix it by checking res_spin_lock_off instead.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Patch Kernel
AI Analysis

Impact

A logic error in the Linux kernel’s BPF subsystem caused the offset guard for the spin‑lock resource to be mistakenly checked against the wrong variable, BPF_SPIN_LOCK, instead of res_spin_lock_off. Based on the description, it is inferred that this flaw can trigger a memory validation bypass, leading to kernel memory corruption if exploited. Such corruption may allow an attacker to overwrite critical kernel data structures, potentially escalating privileges or crashing the system, thereby compromising confidentiality, integrity, and availability.

Affected Systems

All Linux kernel releases that contain the BPF subsystem and do not include the patch commit 04e19012efaec2bfd8c3b37fd8a6c3f1fe731ffc are affected. This includes any vendor distribution of the Linux kernel without the applied fix, regardless of distribution variant. The bug resides in the core kernel code, so any machine running an unpatched kernel is vulnerable.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is execution of a malicious eBPF program from user space that triggers the faulty offset check, which generally requires local or remote code execution with sufficient privileges. As no CVSS score is provided, the exact severity is not quantified, but the potential for kernel memory corruption suggests a high impact if the flaw is exploited.

Generated by OpenCVE AI on September 19, 2026 at 12:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade your Linux kernel to a version that includes commit 04e19012efaec2bfd8c3b37fd8a6c3f1fe731ffc or later, such as the latest kernel release from your distribution.
  • Reboot the system so that the patched kernel is loaded.
  • If patching cannot be performed immediately, limit or disable user-supplied eBPF programs until the kernel is updated, as a temporary mitigation.

Generated by OpenCVE AI on September 19, 2026 at 12:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Fix offset warn check for bpf_res_spin_lock Sashiko pointed out correctly that the case statement for BPF_RES_SPIN_LOCK incorrectly checks offset for BPF_SPIN_LOCK. Fix it by checking res_spin_lock_off instead.
Title bpf: Fix offset warn check for bpf_res_spin_lock
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:24.804Z

Reserved: 2026-09-16T12:21:13.873Z

Link: CVE-2026-92516

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:54.477

Modified: 2026-09-17T17:17:54.477

Link: CVE-2026-92516

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T12:45:16Z

Weaknesses