Description
In the Linux kernel, the following vulnerability has been resolved:

riscv, bpf: Fix kernel stack corruption in tailcall with CFI

When CONFIG_CFI_CLANG is enabled, prog->bpf_func already skips the kcfi
instruction during setup. Including it again in the tailcall jump offset
causes it to jump over an extra 4 bytes, skipping the stack pointer
adjustment, which will result in kernel stack corruption.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel stack corruption leading to privilege escalation or denial of service
Action: Patch Now
AI Analysis

Impact

An error in the RISC‑V BPF implementation causes the kernel stack to be corrupted when tailcall jumps are executed while the CFI Clang policy is enabled. The stray instruction skips a stack pointer adjustment, resulting in a corrupted stack that can lead to arbitrary memory corruption. Based on the description, attackers who can inject or control BPF programs may exploit this bug to corrupt kernel memory, potentially escalating privileges or crashing the system.

Affected Systems

This flaw affects all Linux kernel builds that enable CONFIG_CFI_CLANG on RISC‑V architectures. No specific upstream version numbers are provided, but any kernel incorporating the vulnerable tailcall path is impacted. The issue was fixed in recent commits referenced above; therefore, kernels before those commits are susceptible.

Risk and Exploitability

The CVSS score of 7.8 reflects a high severity. However, the EPSS score of less than 1% suggests a low likelihood of exploitation at this time, and the vulnerability is not included in CISA’s KEV catalog. Based on the description, a likely attack vector involves supplying a malicious BPF program, implying that a local or privileged attacker could potentially trigger the corruption. Patch status is urgent given the potential for kernel compromise.

Generated by OpenCVE AI on September 19, 2026 at 22:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the patch from commit 34b1bb33a025787e05f966e74de18cd36276f801 or later.
  • If upgrading is not immediately possible, disable CONFIG_CFI_CLANG for clang or rebuild the kernel without CFI support for BPF, thereby eliminating the conditional path that triggers the corruption.
  • Avoid using BPF tailcall instructions that rely on the corrected offset until the kernel is patched; alternatively, replace affected BPF programs with versions that do not use tailcalls.

Generated by OpenCVE AI on September 19, 2026 at 22:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Sat, 19 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Sat, 19 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix kernel stack corruption in tailcall with CFI When CONFIG_CFI_CLANG is enabled, prog->bpf_func already skips the kcfi instruction during setup. Including it again in the tailcall jump offset causes it to jump over an extra 4 bytes, skipping the stack pointer adjustment, which will result in kernel stack corruption.
Title riscv, bpf: Fix kernel stack corruption in tailcall with CFI
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:36.191Z

Reserved: 2026-09-16T12:21:13.873Z

Link: CVE-2026-92518

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:54.687

Modified: 2026-09-18T18:18:13.997

Link: CVE-2026-92518

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:45:06Z

Weaknesses