Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max

check_kfunc_args() detects a kfunc argument named rdonly_buf_size or
rdwr_buf_size and stores reg->var_off.value into meta->r0_size, a u64,
and does not bound it. check_kfunc_call() later copies that value into
the returned register's mem_size field:

meta->r0_size = reg->var_off.value;
...
regs[BPF_REG_0].mem_size = meta.r0_size;

regs[BPF_REG_0].mem_size is u32. A constant whose upper 32 bits are set
gets truncated instead of causing a load-time rejection, so the verifier
records a PTR_TO_MEM register with an approximately 4 GiB mem_size for
whatever allocation the kfunc returned. A later access check against
that register uses the truncated, wrong bound.

Reject rdonly_buf_size/rdwr_buf_size values that exceed U32_MAX at the
point meta->r0_size is set.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption
Action: Immediate Patch
AI Analysis

Impact

The kernel’s BPF verifier accepts kfunc arguments named rdonly_buf_size or rdwr_buf_size that exceed the 32‑bit maximum. The verifier stores these values in a 64‑bit field without bounding them and later copies the value into a 32‑bit memory size register, truncating the upper 32 bits. This causes the verifier to record a PTR_TO_MEM register with an incorrectly large memory size, enabling a user to bypass intended bounds checks and potentially read or write beyond the allocated memory region. The flaw directly threatens memory integrity and could lead to data disclosure or corruption if exploited.

Affected Systems

All releases of the Linux kernel before the CVE‑2026‑93125 fix are affected, including the general Linux operating system. The specific version range is not enumerated in the advisory, so any kernel that has not yet applied the upstream patch is considered vulnerable.

Risk and Exploitability

The CVSS base score of 7.8 indicates a high level of risk, while the EPSS score of less than 1 percent suggests a low probability of widespread exploitation at this time. The vulnerability requires an attacker to craft or supply a malicious BPF program that utilizes kfunc arguments exceeding U32_MAX; such a program would then be loaded into the kernel, bypassing normal bounds verification and potentially causing a memory violation. Because the flaw exists in kernel space, privileged execution is a. Nevertheless, the combination of a kernel‑level flaw and a hard‑to‑detect execution path warrants a proactive mitigation strategy.

Generated by OpenCVE AI on September 19, 2026 at 22:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the CVE‑2026‑93125 fix.
  • If a kernel upgrade cannot be applied immediately, enforce a kernel policy that rejects BPF programs or kfunc calls with argument values exceeding the 32‑bit maximum (e.g., by using Auditing or custom policy hooks).
  • Monitor kernel logs for BPF verifier errors or anomalous memory access patterns and enable additional mitigations such as CONFIG_BPF_SYSCALL_FILTER if available to reduce the attack surface.

Generated by OpenCVE AI on September 19, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-197

Sat, 19 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CWE-680

Sat, 19 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CWE-680

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max check_kfunc_args() detects a kfunc argument named rdonly_buf_size or rdwr_buf_size and stores reg->var_off.value into meta->r0_size, a u64, and does not bound it. check_kfunc_call() later copies that value into the returned register's mem_size field: meta->r0_size = reg->var_off.value; ... regs[BPF_REG_0].mem_size = meta.r0_size; regs[BPF_REG_0].mem_size is u32. A constant whose upper 32 bits are set gets truncated instead of causing a load-time rejection, so the verifier records a PTR_TO_MEM register with an approximately 4 GiB mem_size for whatever allocation the kfunc returned. A later access check against that register uses the truncated, wrong bound. Reject rdonly_buf_size/rdwr_buf_size values that exceed U32_MAX at the point meta->r0_size is set.
Title bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:05.805Z

Reserved: 2026-09-17T16:02:15.087Z

Link: CVE-2026-93125

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:07.247

Modified: 2026-09-18T18:18:21.907

Link: CVE-2026-93125

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:11Z

Weaknesses