Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Require a BPF cpumask for bpf_cpumask_populate()

bpf_cpumask_populate() writes to its destination with bitmap_copy(), but
the destination is typed as struct cpumask *. That allows the verifier to
accept borrowed cpumask pointers returned by read-only kfuncs, such as
scx_bpf_get_online_cpumask(), as a writable destination.

Make the destination a struct bpf_cpumask * so populate follows the same
ownership rule as the other mutating cpumask kfuncs. Query kfuncs continue
to accept const struct cpumask * inputs.
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption that could allow privilege escalation
Action: Apply Patch
AI Analysis

Impact

The Linux kernel implementation of bpf_cpumask_populate() allows the helper to write to memory addresses belonging to read‑only cpumask structures. The helper expects a struct cpumask * destination, which the verifier can supply with a borrowed pointer returned by a const kfunc such as scx_bpf_get_online_cpumask(). Because the destination is not typed as a BPF‑specific cpumask, the helper performs bitmap_copy() to a writable address that the kernel is not supposed to modify, leading to arbitrary kernel memory writes and corruption of kernel data structures. This violates the ownership rules for mutable cpumask manipulation and can undermine system integrity. The weakness is related to improper resource handling (CWE‑687) and could enable an attacker to modify privileged data and potentially elevate privileges. The impact is confined to kernel memory; user data is not directly exposed.

Affected Systems

The flaw exists in all Linux kernel releases that include the bpf_cpumask_populate() helper and the associated kfuncs. The vendor is Linux, product Linux kernel. No specific version range is listed in the advisories, so any kernel containing the vulnerable helper should be treated as affected. Users should check the running kernel version against vendor release notes to determine whether the fix is present and plan an upgrade accordingly.

Risk and Exploitability

The CVSS score is 7.1, indicating high severity. The EPSS score is reported as less than 1%, suggesting the likelihood of exploitation is currently low; however, kernel exploitation is a serious threat regardless of current prevalence. The vulnerability is not listed in the CISA KEV catalog, meaning no active exploitation has been documented. The likely attack vector requires an attacker to load a malicious BPF program that calls bpf_cpumask_populate() with a borrowed read‑only cpumask pointer. This requires a local or privileged context that can execute BPF code, but does not depend on additional conditions such as network access or service exposure. Consequently, the risk is moderate to high for systems that allow untrusted BPF program execution or provide local root privileges.

Generated by OpenCVE AI on September 19, 2026 at 22:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the bpf_cpumask_populate() fix.
  • If an immediate kernel update is not feasible, disable or restrict the ability to load BPF programs that invoke bpf_cpumask_populate() using appropriate system controls or security‑module policies.
  • Audit BPF usage and monitor kernel logs for anomalous activity that could indicate an exploitation attempt.

Generated by OpenCVE AI on September 19, 2026 at 22:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-687

Sat, 19 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-687

Sat, 19 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-687

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Require a BPF cpumask for bpf_cpumask_populate() bpf_cpumask_populate() writes to its destination with bitmap_copy(), but the destination is typed as struct cpumask *. That allows the verifier to accept borrowed cpumask pointers returned by read-only kfuncs, such as scx_bpf_get_online_cpumask(), as a writable destination. Make the destination a struct bpf_cpumask * so populate follows the same ownership rule as the other mutating cpumask kfuncs. Query kfuncs continue to accept const struct cpumask * inputs.
Title bpf: Require a BPF cpumask for bpf_cpumask_populate()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:00.309Z

Reserved: 2026-09-17T16:02:15.086Z

Link: CVE-2026-93112

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:05.687

Modified: 2026-09-18T18:18:21.150

Link: CVE-2026-93112

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:45:06Z

Weaknesses
  • CWE-687

    Function Call With Incorrectly Specified Argument Value