Description
In the Linux kernel, the following vulnerability has been resolved:

bpf, riscv: Fix extable handling for arena load_acquire

emit_atomic_ld_st() returns 1 to have build_body() skip the zext after
a sub-word load_acquire. The caller does "ret = ret ?:
add_exception_handler(...)", which skips add_exception_handler() on any
non-zero ret, so the extable entry is missing and a faulting
PROBE_ATOMIC load_acquire oopses.

REG_DONT_CLEAR_MARKER leaves rd stale on fault, and the verifier still
thinks the load overwrote it, so a program can leak it through a map.

Check ret >= 0 before calling add_exception_handler(), and pass rd for
LOAD_ACQ so the fault zeroes rd like a PROBE_MEM load. Return ret
unchanged for the zext skip.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Local Denial of Service and Information Leakage
Action: Patch Kernel
AI Analysis

Impact

The vulnerability is found in the Linux kernel’s BPF subsystem for RISC‑V, where the handling of an atomic load_acquire operation incorrectly skips adding an exception table entry. This omission causes a faulting PROBE_ATOMIC load_acquire to trigger a kernel oops. In addition, when the fault occurs the stale register value is not cleared, and the verifier still believes the load overwrote it, potentially allowing that register content to leak through a map to user space. The flaw is local and requires execution of a BPF program, but it can result in a kernel crash and disclosure of internal register data.

Affected Systems

All Linux kernel installations running on RISC‑V hardware that use the BPF verifier for load_acquire operations are affected, up to the commit that fixed the extable handling bug. The issue resides in the kernel’s BPF component, so all distributions shipping an unpatched RISC‑V kernel are potentially exposed. No specific kernel version numbers are provided in the data, but any release prior to the fix commit is impacted.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating overall low likelihood of exploitation at present. Based on the description, the likely attack vector is local: an attacker who can load a malicious BPF program—typically requiring elevated privileges or a kernel escape—can trigger the fault. This could lead to a local denial of service by crashing the kernel or exposing sensitive register contents to user space.

Generated by OpenCVE AI on September 19, 2026 at 13:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the commit fixing the extable handling bug for RISC‑V BPF load_acquire operations.
  • Reboot the system or reload the kernel modules to ensure the patch is active.
  • Restrict BPF program loading and enforce strict verification policies so that only trusted users can load programs that might fault on load_acquire operations.

Generated by OpenCVE AI on September 19, 2026 at 13:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf, riscv: Fix extable handling for arena load_acquire emit_atomic_ld_st() returns 1 to have build_body() skip the zext after a sub-word load_acquire. The caller does "ret = ret ?: add_exception_handler(...)", which skips add_exception_handler() on any non-zero ret, so the extable entry is missing and a faulting PROBE_ATOMIC load_acquire oopses. REG_DONT_CLEAR_MARKER leaves rd stale on fault, and the verifier still thinks the load overwrote it, so a program can leak it through a map. Check ret >= 0 before calling add_exception_handler(), and pass rd for LOAD_ACQ so the fault zeroes rd like a PROBE_MEM load. Return ret unchanged for the zext skip.
Title bpf, riscv: Fix extable handling for arena load_acquire
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:25.482Z

Reserved: 2026-09-16T12:21:13.873Z

Link: CVE-2026-92517

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:54.587

Modified: 2026-09-17T17:17:54.587

Link: CVE-2026-92517

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:15:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor