Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject arena frees below the arena base

bpf_arena_free_pages() accepts scalar arena addresses. The runtime
masks the address to the low 32 bits and reconstructs a full user
address from the arena base before returning the range to the arena
free tree.

When the scalar value is below the low 32 bits of the arena base,
full_uaddr falls below user_vm_start. The existing upper-end clipping
then turns this into an out-of-range free-tree offset. A later
allocation can reuse that offset and return an address below the arena
mapping.

Reject such frees before computing the clipped range.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption that could lead to privilege escalation
Action: Immediate patch
AI Analysis

Impact

The Linux kernel’s BPF arena free routine, bpf_arena_free_pages(), accepts scalar arena addresses that are masked to the low 32 bits before reconstructing a full user address from the arena base. When the scalar value is below the low‑32‑bits of the arena base, the reconstructed address falls below user_vm_start. The existing upper‑end clipping then converts this to an out‑of‑range free‑tree offset. A subsequent allocation can reuse that offset, returning a kernel pointer that is below the arena mapping, which can corrupt kernel memory and potentially allow an attacker to execute code with root privileges.

Affected Systems

All Linux kernel releases before the patch referenced in the CVE description are affected. The vulnerability is present in the general Linux kernel, affecting any system that loads BPF programs and uses arena allocation.This includes both upstream kernel versions and the kernel shipped by most Linux distributions until the patch is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score of <1% suggests that exploitation of this bug in the wild is currently unlikely. The issue is not listed in CISA’s KEV catalog. Exploitation would require a privileged local attacker capable of loading a crafted BPF program that triggers the free mechanism; it is not a remotely exploitable flaw.

Generated by OpenCVE AI on September 19, 2026 at 16:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the commit that resolves the arena free issue (e.g., kernel version 6.5 or later based on the linked Git commits).
  • If an immediate kernel upgrade is not possible, restrict the use of BPF programs to trusted users only by applying appropriate Linux security controls such as SELinux policies or AppArmor profiles that disallow bpf() system calls for untrusted processes.
  • Regularly audit kernel logs for any unexpected bpf arena free operations or memory corruption warnings and enable CONFIG_DEBUG_KMEM or similar debugging features to detect anomalous free offsets early.

Generated by OpenCVE AI on September 19, 2026 at 16:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-129
CWE-665

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Reject arena frees below the arena base bpf_arena_free_pages() accepts scalar arena addresses. The runtime masks the address to the low 32 bits and reconstructs a full user address from the arena base before returning the range to the arena free tree. When the scalar value is below the low 32 bits of the arena base, full_uaddr falls below user_vm_start. The existing upper-end clipping then turns this into an out-of-range free-tree offset. A later allocation can reuse that offset and return an address below the arena mapping. Reject such frees before computing the clipped range.
Title bpf: Reject arena frees below the arena base
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:45.700Z

Reserved: 2026-09-17T15:57:05.658Z

Link: CVE-2026-93045

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:57.743

Modified: 2026-09-18T18:18:19.097

Link: CVE-2026-93045

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T16:15:13Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index

  • CWE-665

    Improper Initialization