Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux

bpf_get_btf_vmlinux() lazily parses the vmlinux BTF under the
bpf_verifier_lock, but publishes the result through a plain store
and re-checks it through a plain lockless load. Nothing orders
the stores initializing the struct btf inside btf_parse_vmlinux()
against the store publishing the pointer: On a weakly ordered
arch, a concurrent first-time caller taking the lockless fast
path could in principle observe the pointer before the parsed
contents are visible. The mutex_unlock() does not help such a
reader given it only synchronizes with a later acquisition of the
same lock. Thus, publish the pointer with smp_store_release()
and read it on the fast path with smp_load_acquire().

Acquire semantics are needed rather than a dependency-ordered
READ_ONCE(): btf_parse_vmlinux() also populates globals outside
the returned object (e.g. bpf_ctx_convert.t). An address
dependency would only order accesses performed through the
pointer and not cover other globals.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Race condition potentially compromising kernel integrity
Action: Immediate Patch
AI Analysis

Impact

A race condition exists in the Linux kernel’s BPF verifier when it lazily parses the vmlinux BTF data. The pointer to the parsed structure is released through a plain store while the contents are still being initialized. On weakly ordered architectures, a concurrent caller that bypasses the lock can see an uninitialized pointer and later read incomplete or stale data, potentially exposing kernel memory to unintended observers. This race is an example of improper initialization weakness, which could allow malicious code to exploit kernel data structures before they are safely constructed.

Affected Systems

All current mainline releases of the Linux kernel that include the BPF BTF loader and use the bpf_get_btf_vmlinux function are vulnerable until the smp_store_release/smp_load_acquire changes are applied. The advisory does not specify individual version ranges, so any kernel version from the last stable commit before the patch is considered affected.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, yet the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a presently low probability of exploitation. The race would be triggered by simultaneous BPF program loading on a weakly ordered CPU, and the advisory does not provide evidence of a direct attack path. Consequently, while the impact is potentially significant, the exploitation likelihood remains uncertain without further evidence.

Generated by OpenCVE AI on September 19, 2026 at 15:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that contains the smp_store_release/smp_load_acquire fixes for bpf_get_btf_vmlinux
  • Limit BPF program loading to trusted users or disable BPF BTF features if they are unnecessary
  • Watch kernel logs for abnormal BPF behavior and apply updates promptly

Generated by OpenCVE AI on September 19, 2026 at 15:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux bpf_get_btf_vmlinux() lazily parses the vmlinux BTF under the bpf_verifier_lock, but publishes the result through a plain store and re-checks it through a plain lockless load. Nothing orders the stores initializing the struct btf inside btf_parse_vmlinux() against the store publishing the pointer: On a weakly ordered arch, a concurrent first-time caller taking the lockless fast path could in principle observe the pointer before the parsed contents are visible. The mutex_unlock() does not help such a reader given it only synchronizes with a later acquisition of the same lock. Thus, publish the pointer with smp_store_release() and read it on the fast path with smp_load_acquire(). Acquire semantics are needed rather than a dependency-ordered READ_ONCE(): btf_parse_vmlinux() also populates globals outside the returned object (e.g. bpf_ctx_convert.t). An address dependency would only order accesses performed through the pointer and not cover other globals.
Title bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:10.073Z

Reserved: 2026-09-17T16:02:15.088Z

Link: CVE-2026-93138

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:08.720

Modified: 2026-09-18T18:18:22.363

Link: CVE-2026-93138

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:00:21Z

Weaknesses