Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Copy per-CPU map value padding in copy_map_value_long()

In kernel, per-CPU map elements are stored with
round_up(map->value_size, 8) bytes. On UAPI lookup paths, it copies the
rounded size for each CPU into a temporary buffer.

However, copy_map_value_long() passes 'map->value_size' to
bpf_obj_memcpy(). When the map has special fields, bpf_obj_memcpy() copies
around those fields with memcpy(), and does not copy the tail padding
between 'map->value_size' and round_up(map->value_size, 8).

The temporary UAPI lookup buffers are allocated without __GFP_ZERO. As a
result, when the per-CPU map's value size is not equal to
round_up(map->value_size, 8), UAPI LOOKUP_ELEM and its variants can return
stale heap contents from that padding to user space. The same issue
applies to bpf_iter for per-CPU maps.

Pass round_up(map->value_size, 8) to bpf_obj_memcpy() from
copy_map_value_long(), so per-CPU maps both with and without special
fields copy the entire per-CPU slot. Remove the now redundant round_up()
from bpf_obj_memcpy()'s long_memcpy path.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Update Kernel
AI Analysis

Impact

The vulnerability arises from per‑CPU BPF map elements being stored with a padded size that is rounded up to the nearest multiple of eight bytes. When a lookup occurs via the UAPI, the kernel copies only the unpadded value into a temporary buffer but the buffer itself is not zeroed. The unused padding area may contain stale heap data, which is then returned to user space. An attacker able to perform a BPF lookup on a per‑CPU map can therefore read unintended memory contents, exposing sensitive data that was never meant for user space.

Affected Systems

All Linux kernel releases that contain the per-CPU BPF map implementation are affected. The vulnerability is present in the generic Linux kernel.

Risk and Exploitability

The EPSS score is under 1 %, indicating a low probability of exploitation at present. The CVE is not listed in the CISA KEV catalog. The vulnerability is local: it requires a process that can load BPF programs and has access to per‑CPU maps, which is typically a privileged or specially allowed user. Exploitation would result in data disclosure rather than code execution or denial of service. The lack of a publicly known exploit and the low EPSS score suggest the immediate risk is low, but the information disclosure could aid in credential or privilege escalation if combined with other weaknesses.

Generated by OpenCVE AI on September 19, 2026 at 08:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the patch correcting copy_map_value_long() to use the rounded size for memory copies
  • If an update cannot be applied immediately, limit the creation and access of per‑CPU BPF maps to trusted processes only and revoke standard user permissions to perform BPF lookups
  • Monitor system logs for unusual BPF map access patterns and investigate any anomalies that could indicate exploitation attempts

Generated by OpenCVE AI on September 19, 2026 at 08:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Copy per-CPU map value padding in copy_map_value_long() In kernel, per-CPU map elements are stored with round_up(map->value_size, 8) bytes. On UAPI lookup paths, it copies the rounded size for each CPU into a temporary buffer. However, copy_map_value_long() passes 'map->value_size' to bpf_obj_memcpy(). When the map has special fields, bpf_obj_memcpy() copies around those fields with memcpy(), and does not copy the tail padding between 'map->value_size' and round_up(map->value_size, 8). The temporary UAPI lookup buffers are allocated without __GFP_ZERO. As a result, when the per-CPU map's value size is not equal to round_up(map->value_size, 8), UAPI LOOKUP_ELEM and its variants can return stale heap contents from that padding to user space. The same issue applies to bpf_iter for per-CPU maps. Pass round_up(map->value_size, 8) to bpf_obj_memcpy() from copy_map_value_long(), so per-CPU maps both with and without special fields copy the entire per-CPU slot. Remove the now redundant round_up() from bpf_obj_memcpy()'s long_memcpy path.
Title bpf: Copy per-CPU map value padding in copy_map_value_long()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:12:03.946Z

Reserved: 2026-09-17T16:02:15.090Z

Link: CVE-2026-93174

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:13.167

Modified: 2026-09-17T17:18:13.167

Link: CVE-2026-93174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor