Impact
The kernel’s BPF verifier accepts kfunc arguments named rdonly_buf_size or rdwr_buf_size that exceed the 32‑bit maximum. The verifier stores these values in a 64‑bit field without bounding them and later copies the value into a 32‑bit memory size register, truncating the upper 32 bits. This causes the verifier to record a PTR_TO_MEM register with an incorrectly large memory size, enabling a user to bypass intended bounds checks and potentially read or write beyond the allocated memory region. The flaw directly threatens memory integrity and could lead to data disclosure or corruption if exploited.
Affected Systems
All releases of the Linux kernel before the CVE‑2026‑93125 fix are affected, including the general Linux operating system. The specific version range is not enumerated in the advisory, so any kernel that has not yet applied the upstream patch is considered vulnerable.
Risk and Exploitability
The CVSS base score of 7.8 indicates a high level of risk, while the EPSS score of less than 1 percent suggests a low probability of widespread exploitation at this time. The vulnerability requires an attacker to craft or supply a malicious BPF program that utilizes kfunc arguments exceeding U32_MAX; such a program would then be loaded into the kernel, bypassing normal bounds verification and potentially causing a memory violation. Because the flaw exists in kernel space, privileged execution is a. Nevertheless, the combination of a kernel‑level flaw and a hard‑to‑detect execution path warrants a proactive mitigation strategy.
OpenCVE Enrichment