Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Drop scalar id on sign-extending narrowing stack fills

When a spilled scalar is filled back with a sign-extending narrowing load
(BPF_MEMSX), check_stack_read_fixed_off() copies the spilled register
including its scalar id, but coerce_reg_to_size_sx() then sign-extends the
filled register's value. If the same slot is also filled with a plain
zero-extending load (BPF_MEM), both destination registers share the id yet
hold different values. A later 'if <zext-reg> == const' then refines the
sign-extended register through sync_linked_regs() to a value it does not
have at runtime (e.g. the verifier believes 0x80000000 while the register
is 0xffffffff80000000), which can be turned into an out-of-bounds access.

Drop the shared scalar id at the sign-extension site in check_mem_access()
when sign extension actually changes the value, mirroring the BPF_MOVSX
handling in check_alu_op() (no_sext = reg_umax < 2^(size*8-1)).
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption leading to out-of-bounds access
Action: Upgrade kernel
AI Analysis

Impact

In the Linux kernel, the BPF verifier can incorrectly preserve a scalar identifier when a spilled register is reloaded using a sign‑extending narrow load (BPF_MEMSX). This flaw involves CWE‑125, CWE‑195, and CWE‑680 and results in the verifier believing that a subsequent zero‑extending load has replaced the value, while the actual register holds a different, sign‑extended value. The verifier may then refine conditions based on the wrong value and allow an out‑of‑bounds memory access to be compiled into the BPF program. The flaw can lead to memory corruption.

Affected Systems

All Linux kernel releases that contain the BPF verifier logic prior to the patch documented in this advisory are affected. The exact version range is not specified in the data, so any kernel build before the release that applied the fix must be evaluated. The issue touches the core BPF subsystem and therefore applies to all distributions that ship the upstream kernel without the upstream patch.

Risk and Exploitability

The CVSS score of 7.8 places the flaw in the high‑severity range, but the EPSS score of less than 1% indicates a low probability of active exploits at this time. The vulnerability is not listed in CISA's KEV catalog, suggesting no known active exploitation campaigns. An attacker would need to craft a BPF program that triggers the verifier’s sign‑extension logic, which typically requires privileged access to load custom eBPF programs. Consequently, the practical risk is limited to systems that allow untrusted users to load BPF code or that have an unpatched kernel.

Generated by OpenCVE AI on September 20, 2026 at 00:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that removes the shared scalar identifier at the sign‑extension site.
  • If immediate patching is not possible, disable non‑privileged BPF program loading by setting the appropriate sysctl or by restricting the bpf system call to privileged users only.
  • Monitor kernel logs for BPF verifier failures and unusual memory accesses that could indicate exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 00:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-195
CWE-680

Sat, 19 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-195
CWE-680

Sat, 19 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-195
CWE-680

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Drop scalar id on sign-extending narrowing stack fills When a spilled scalar is filled back with a sign-extending narrowing load (BPF_MEMSX), check_stack_read_fixed_off() copies the spilled register including its scalar id, but coerce_reg_to_size_sx() then sign-extends the filled register's value. If the same slot is also filled with a plain zero-extending load (BPF_MEM), both destination registers share the id yet hold different values. A later 'if <zext-reg> == const' then refines the sign-extended register through sync_linked_regs() to a value it does not have at runtime (e.g. the verifier believes 0x80000000 while the register is 0xffffffff80000000), which can be turned into an out-of-bounds access. Drop the shared scalar id at the sign-extension site in check_mem_access() when sign extension actually changes the value, mirroring the BPF_MOVSX handling in check_alu_op() (no_sext = reg_umax < 2^(size*8-1)).
Title bpf: Drop scalar id on sign-extending narrowing stack fills
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:07.215Z

Reserved: 2026-09-17T16:02:15.087Z

Link: CVE-2026-93127

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:07.460

Modified: 2026-09-18T18:18:22.070

Link: CVE-2026-93127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:15:06Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-195

    Signed to Unsigned Conversion Error

  • CWE-680

    Integer Overflow to Buffer Overflow