Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject writes through untrusted BTF pointers

check_ptr_to_btf_access() lets program-type btf_struct_access callbacks
validate writes before the default BTF access path rejects non-read
accesses. That bypasses the read-only policy for untrusted BTF pointers
created by helpers such as bpf_rdonly_cast().

Reject non-read accesses through PTR_UNTRUSTED BTF pointers at the
common entry point, before the callback branch to handle all cases.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel BPF subsystem allows program-type callbacks to validate writes to BTF pointers before the default access path rejects non‑read operations. This bypasses the intended read‑only policy for untrusted pointers created by helper functions such as bpf_rdonly_cast. The result is that a BPF program can write to kernel memory through an untrusted BTF pointer, which violates the kernel’s access control. Based on the description, it is inferred that this flaw could allow an attacker to corrupt kernel data and potentially elevate privileges.

Affected Systems

Linux kernel installations that have not incorporated the commit referenced in the advisory are affected. The advisory lists Linux as the vendor and the Linux kernel as the product. No specific version range is supplied, so the flaw applies to any kernel prior to the commit that adds the rejection of non‑read accesses for untrusted BTF pointers.

Risk and Exploitability

The CVSS score of 7.8 indicates a medium‑to‑high level of severity. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, and no public exploits are known. Based on the description, it is inferred that the likely attack vector would involve loading a BPF program that uses untrusted BTF pointers, which typically requires local or elevated privileges. The overall risk is moderate, but the potential impact warrants prompt remediation if the system has not been patched.

Generated by OpenCVE AI on September 20, 2026 at 01:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that contains the BPF pointer validation fix from the official upstream repository.
  • If a kernel upgrade is not possible, restrict or disable loading of BPF programs that use untrusted BTF pointers by enforcing stricter control and disabling helpers such as bpf_rdonly_cast through policy or seccomp.
  • If custom or third‑party BPF programs are used, audit them for the use of bpf_rdonly_cast or similar helpers and modify them to use trusted BTF contexts before deployment.

Generated by OpenCVE AI on September 20, 2026 at 01:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284

Sat, 19 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284

Sat, 19 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284

Sat, 19 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Reject writes through untrusted BTF pointers check_ptr_to_btf_access() lets program-type btf_struct_access callbacks validate writes before the default BTF access path rejects non-read accesses. That bypasses the read-only policy for untrusted BTF pointers created by helpers such as bpf_rdonly_cast(). Reject non-read accesses through PTR_UNTRUSTED BTF pointers at the common entry point, before the callback branch to handle all cases.
Title bpf: Reject writes through untrusted BTF pointers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:11.444Z

Reserved: 2026-09-17T16:02:15.088Z

Link: CVE-2026-93144

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:09.507

Modified: 2026-09-18T18:18:22.530

Link: CVE-2026-93144

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:45:17Z

Weaknesses

No weakness.