Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject MEM_ALLOC BTF accesses past object bounds

BTF struct walks relax the struct-size check for accesses through a
trailing flexible array. That is valid for ordinary BTF type walking, but
PTR_TO_BTF_ID | MEM_ALLOC values point to objects allocated with the static
BTF type size.

When walking a MEM_ALLOC object, reject the access before applying the
flexible-array relaxation if the access range extends past the struct size.
Apply the same policy to struct ID matching so kfunc and kptr type checks
do not walk past the allocated object bounds either.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds Read
Action: Patch
AI Analysis

Impact

The Linux kernel contains a flaw in the handling of BPF Type Format (BTF) structure walks. The kernel relaxes the struct‑size check for accesses through a trailing flexible array, which is acceptable for normal BTF type walking but mistakenly allows the same relaxation for MEM_ALLOC objects whose BTF type size is static. When a loader walks a MEM_ALLOC object, the kernel rejects the access only after applying the flexible‑array relaxation, permitting the code to read past the bounds of the allocated kernel buffer. This results in an out‑of‑bounds read that can leak kernel memory contents. The vulnerability is a classic buffer overread and does not provide a direct path to code execution.

Affected Systems

All Linux kernel distributions that include kernel versions prior to the fix are affected. The vendor is Linux and the product is the Linux kernel. No specific version range is provided in the advisory, so any kernel version older than the patched release should be considered vulnerable.

Risk and Exploitability

The EPSS score is below 1%, indicating a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 7.8 denotes high severity. Based on the description, it is inferred that an attacker must be able to load a malicious eBPF program to trigger the out‑of‑bounds read, implying a local or privileged attack context. No evidence of remote exploitation is present in the advisory.

Generated by OpenCVE AI on September 19, 2026 at 22:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the MEM_ALLOC BTF bound‑check fix
  • Restrict eBPF program loading to privileged users or implement kernel security modules to prevent unauthorized BPF program installation
  • Audit existing BPF programs for unsafe memory accesses and disable them if they are not required

Generated by OpenCVE AI on September 19, 2026 at 22:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Sat, 19 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Sat, 19 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Reject MEM_ALLOC BTF accesses past object bounds BTF struct walks relax the struct-size check for accesses through a trailing flexible array. That is valid for ordinary BTF type walking, but PTR_TO_BTF_ID | MEM_ALLOC values point to objects allocated with the static BTF type size. When walking a MEM_ALLOC object, reject the access before applying the flexible-array relaxation if the access range extends past the struct size. Apply the same policy to struct ID matching so kfunc and kptr type checks do not walk past the allocated object bounds either.
Title bpf: Reject MEM_ALLOC BTF accesses past object bounds
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:14.130Z

Reserved: 2026-09-17T16:02:15.088Z

Link: CVE-2026-93148

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:09.977

Modified: 2026-09-18T18:18:22.760

Link: CVE-2026-93148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:00:10Z

Weaknesses