Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject programs with inlined helpers if JIT is not available

When an architecture (such as LoongArch, ARM64, and RISC-V) implements
bpf_jit_inlines_helper_call(), the verifier skips rewriting the helper
call offset (insn->imm) in bpf_do_misc_fixups(). This is because the
helper is expected to be inlined by the JIT compiler later. Therefore,
insn->imm remains as the raw helper enum ID.

However, if JIT is disabled at runtime (net.core.bpf_jit_enable=0) or
if JIT compilation fails dynamically (e.g., due to OOM), the program
falls back to the BPF interpreter.

When the interpreter executes (__bpf_call_base + insn->imm) with the
unpatched raw ID, it jumps into an invalid address space, triggering
an instruction alignment fault or a kernel panic.

Although these helpers have valid C implementations in the kernel, the
omission of offset rewriting makes runtime interpreter fallback fatal.

Fix this by setting 'prog->jit_required = 1' when helper call rewriting
is skipped for JIT inlining. This ensures that such programs are safely
rejected if JIT is not available, preventing the runtime kernel panic.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel panic leading to denial of service
Action: Patch Immediately
AI Analysis

Impact

When a Linux kernel architecture such as LoongArch, ARM64, or RISC‑V implements bpf_jit_inlines_helper_call, the verifier skips rewriting the helper call offset in the BPF interpreter path. If JIT is disabled or fails at runtime, the interpreter executes the raw helper enum ID, which jumps to an invalid address. The execution of this invalid address triggers an instruction alignment fault or directly causes a kernel panic. The vulnerability is a consequence of improper initialization of program metadata that allows a control‑flow error. An attacker who can load a BPF program on the affected kernel can force the system to crash, resulting in a denial of service.

Affected Systems

All Linux kernel builds that contain the bpf_jit_inlines_helper_call feature for architectures such as LoongArch, ARM64, and RISC‑V are affected. This covers every kernel release prior to the patch that enforces prog->jit_required=1. No distribution‑specific version limits are listed, so any system running an unpatched kernel with the inlining capability is vulnerable.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low current exploitation probability. Exploitation requires the ability to inject or load a BPF program, which typically necessitates elevated privileges or a separate software flaw that permits BPF code submission. Once the program is present, an attacker can trigger the interpreter fallback by disabling JIT (net.core.bpf_jit_enable = 0) or by causing a compiler failure such as an out‑of‑memory condition. Remote exploitation would need an additional vector that allows BPF program loading; otherwise the impact remains limited to privileged local attacks.

Generated by OpenCVE AI on September 19, 2026 at 13:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that implements the BPF JIT inlining fix, which sets prog->jit_required to 1
  • Keep the kernel option net.core.bpf_jit_enable set to a non‑zero value and avoid disabling JIT unless absolutely necessary
  • Restrict BPF program loading to trusted users only, for example by requiring CAP_SYS_ADMIN or equivalent capabilities and monitor kernel logs for BPF‑related panics

Generated by OpenCVE AI on September 19, 2026 at 13:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Reject programs with inlined helpers if JIT is not available When an architecture (such as LoongArch, ARM64, and RISC-V) implements bpf_jit_inlines_helper_call(), the verifier skips rewriting the helper call offset (insn->imm) in bpf_do_misc_fixups(). This is because the helper is expected to be inlined by the JIT compiler later. Therefore, insn->imm remains as the raw helper enum ID. However, if JIT is disabled at runtime (net.core.bpf_jit_enable=0) or if JIT compilation fails dynamically (e.g., due to OOM), the program falls back to the BPF interpreter. When the interpreter executes (__bpf_call_base + insn->imm) with the unpatched raw ID, it jumps into an invalid address space, triggering an instruction alignment fault or a kernel panic. Although these helpers have valid C implementations in the kernel, the omission of offset rewriting makes runtime interpreter fallback fatal. Fix this by setting 'prog->jit_required = 1' when helper call rewriting is skipped for JIT inlining. This ensures that such programs are safely rejected if JIT is not available, preventing the runtime kernel panic.
Title bpf: Reject programs with inlined helpers if JIT is not available
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:36.771Z

Reserved: 2026-09-17T16:02:15.087Z

Link: CVE-2026-93135

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:08.373

Modified: 2026-09-17T17:18:08.373

Link: CVE-2026-93135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T16:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-665

    Improper Initialization