Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Disallow interpreter fallback for arena-related insns

Since the interpreter does not support the arena-related insns,
interpreter fallback should not be allowed for these insns in
core.c::__bpf_prog_select_runtime().

Currently, when the interpreter executes the arena ST/LDX/STX insns,
it would hit the BUG_ON() in ___bpf_prog_run() at run time.

[ 2.579196] BPF interpreter: unknown opcode a2 (imm: 0x0)
[ 2.579998] ------------[ cut here ]------------
[ 2.580652] kernel BUG at kernel/bpf/core.c:2349!
[ 2.581314] Oops: invalid opcode: 0000 [#1] SMP PTI

Set jit_required as true when arena map is used in the prog to disallow
interpreter fallback for arena-related insns.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash and denial of service
Action: Apply patch
AI Analysis

Impact

The Linux kernel BPF interpreter incorrectly allows fallback for arena-related instructions such as ST/LDX/STX. Because these operations are unsupported by the interpreter, executing them triggers a BUG_ON assertion that causes a kernel panic. The issue manifests when a BPF program containing an unsupported opcode is loaded and executed. This flaw represents a defect classified as CWE-398.

Affected Systems

All implementations of the Linux kernel are affected, as indicated by the generic CPE string for the Linux kernel. No specific version range is listed, so any kernel version prior to the applied fix may be vulnerable. Products and distributions that ship the default kernel without the recent patch are at risk.

Risk and Exploitability

The EPSS score for this vulnerability is less than 1%, indicating a low probability of widespread exploitation. It is not listed in the CISA KEV catalog. Exploitation would require the ability to load a crafted BPF program that uses arena instructions; the likely attack vector is local or remote with sufficient permissions to load BPF programs. This inference is based on the requirement that a BPF program must be loaded to trigger the BUG_ON. Once triggered, the failure path leads to a kernel panic, which effectively denies service.

Generated by OpenCVE AI on September 19, 2026 at 12:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that contains the bpf interpreter fix
  • Configure BPF programs that use arena maps to set jit_required to true, which disables interpreter fallback for those instructions
  • Consider disabling BPF interpreter usage or limiting BPF program execution through kernel boot parameters or sysctl settings to mitigate accidental crashes

Generated by OpenCVE AI on September 19, 2026 at 12:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-398

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow interpreter fallback for arena-related insns Since the interpreter does not support the arena-related insns, interpreter fallback should not be allowed for these insns in core.c::__bpf_prog_select_runtime(). Currently, when the interpreter executes the arena ST/LDX/STX insns, it would hit the BUG_ON() in ___bpf_prog_run() at run time. [ 2.579196] BPF interpreter: unknown opcode a2 (imm: 0x0) [ 2.579998] ------------[ cut here ]------------ [ 2.580652] kernel BUG at kernel/bpf/core.c:2349! [ 2.581314] Oops: invalid opcode: 0000 [#1] SMP PTI Set jit_required as true when arena map is used in the prog to disallow interpreter fallback for arena-related insns.
Title bpf: Disallow interpreter fallback for arena-related insns
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:36.285Z

Reserved: 2026-09-17T15:57:05.658Z

Link: CVE-2026-93044

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:57.643

Modified: 2026-09-17T17:17:57.643

Link: CVE-2026-93044

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T12:45:16Z

Weaknesses