Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Disallow interpreter fallback for gotox insn

The interpreter does not recognize the BPF_JMP|BPF_JA|BPF_X insn, which
is used for insn_array map. Thereafter, it would hit the BUG_ON() in
___bpf_prog_run() at run time.

[ 2.563726] BPF interpreter: unknown opcode 0d (imm: 0x0)
[ 2.564557] ------------[ cut here ]------------
[ 2.565206] kernel BUG at kernel/bpf/core.c:2349!
[ 2.565882] Oops: invalid opcode: 0000 [#1] SMP PTI

Set jit_required as true when insn_array map is used in the prog in
order to disallow interpreter fallback for gotox insn in
core.c::__bpf_prog_select_runtime().
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash)
Action: Apply Patch
AI Analysis

Impact

The Linux kernel’s BPF interpreter does not understand the BPF_JMP|BPF_JA|BPF_X opcode used with the insn_array map. When a program containing this instruction is loaded, the interpreter triggers a BUG_ON in ___bpf_prog_run(), causing an oops and a kernel panic. The result is a local denial of service: the affected host becomes unusable until the system is rebooted or the kernel is fixed.

Affected Systems

All Linux kernel installations that have not applied the commit that disables interpreter fallback for the gotox instruction are vulnerable. This includes every distribution kernel version released before the patch commit 17da80d0c7b5. Services that compile or load BPF programs, such as networking devices, container runtimes, or system utilities, can trigger the fault if they use the insn_array map without the mitigation in place.

Risk and Exploitability

The EPSS score is under 1 % and the vulnerability is not in CISA’s KEV catalog, indicating a low current exploitation probability. No CVSS score has been assigned. The flaw requires local or privileged access to load a malicious BPF program, so the impact remains confined to the target machine. If such access is obtained, the attacker can achieve a DoS by forcing the kernel to crash, which disrupts all services on that host.

Generated by OpenCVE AI on September 19, 2026 at 13:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a release that includes the commit disabling interpreter fallback for the gotox opcode.
  • If an upgrade is not immediately possible, mark all BPF programs that use the insn_array map with jit_required=true so the JIT compiler is used and the interpreter is bypassed.
  • As a temporary protection, restrict BPF program loading by disabling the bpf module, applying SELinux or AppArmor restrictions, or denying access to the setfsgid/BPF syscall for untrusted users.

Generated by OpenCVE AI on September 19, 2026 at 13:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow interpreter fallback for gotox insn The interpreter does not recognize the BPF_JMP|BPF_JA|BPF_X insn, which is used for insn_array map. Thereafter, it would hit the BUG_ON() in ___bpf_prog_run() at run time. [ 2.563726] BPF interpreter: unknown opcode 0d (imm: 0x0) [ 2.564557] ------------[ cut here ]------------ [ 2.565206] kernel BUG at kernel/bpf/core.c:2349! [ 2.565882] Oops: invalid opcode: 0000 [#1] SMP PTI Set jit_required as true when insn_array map is used in the prog in order to disallow interpreter fallback for gotox insn in core.c::__bpf_prog_select_runtime().
Title bpf: Disallow interpreter fallback for gotox insn
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:35.602Z

Reserved: 2026-09-17T15:57:05.657Z

Link: CVE-2026-93043

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:57.543

Modified: 2026-09-17T17:17:57.543

Link: CVE-2026-93043

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:15:16Z

Weaknesses
  • CWE-20

    Improper Input Validation