Description
In the Linux kernel, the following vulnerability has been resolved:

s390/bpf: Replace ly instruction with llgf

cpu_nr is a 32 bit value and BPF_REG_0 is a 64 bit register, when ly loads
the cpu_nr into BPF_REG_0 it does not zero the upper bits, but llgf does.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: BPF Register Corruption
Action: Patch immediately
AI Analysis

Impact

In the Linux kernel on s390 machines, the BPF "ly" instruction fails to zero the upper 32 bits of a 64‑bit BPF register when loading a 32‑bit cpu_nr. The subsequent replacement instruction llgf correctly zeros the upper bits, but the unpatched code leaves garbage data in the high part of BPF_REG_0. This register corruption can cause BPF programs to behave unpredictably or incorrectly, potentially leading to system integrity problems or denial of service.

Affected Systems

It is inferred that all Linux kernel releases for the s390 architecture that have not applied the patch replacing "ly" with "llgf" are affected. This includes the mainline kernel and distribution kernels that contain the unpatched code. No specific version range is given, so any kernel containing the unmodified instruction is vulnerable.

Risk and Exploitability

The CVSS score of 7.8 marks the issue as High severity, yet the EPSS score of < 1 % indicates a very low probability of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the ability to load a custom BPF program into the kernel; therefore, only systems that permit untrusted BPF loading pose the greatest risk. Because the flaw resides in the bpf interpreter, it is unlikely to provide privilege escalation, but the corrupted register can affect the logic of BPF programs and potentially disrupt kernel operations.

Generated by OpenCVE AI on September 20, 2026 at 03:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that replaces the "ly" instruction with "llgf".
  • If an immediate update is not possible, restrict or disable BPF program loading to prevent execution of untrusted code.
  • Enforce BPF access controls through SELinux, AppArmor, or a similar policy framework to limit BPF loading to privileged users.

Generated by OpenCVE AI on September 20, 2026 at 03:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Sun, 20 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Sat, 19 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-682 CWE-665

Sat, 19 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-682

Sat, 19 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-682

Sat, 19 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-682

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: s390/bpf: Replace ly instruction with llgf cpu_nr is a 32 bit value and BPF_REG_0 is a 64 bit register, when ly loads the cpu_nr into BPF_REG_0 it does not zero the upper bits, but llgf does.
Title s390/bpf: Replace ly instruction with llgf
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:12.784Z

Reserved: 2026-09-17T16:02:15.088Z

Link: CVE-2026-93147

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:09.867

Modified: 2026-09-18T18:18:22.650

Link: CVE-2026-93147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:00:09Z

Weaknesses