« Volver al listado

CVE-2026-90195

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

riscv, bpf: Fix missing sign-ext for signed 1-byte and 2-byte kfunc args

On RV64, the ABI requires sign-extension for signed 1-byte and 2-byte kfunc args. However, the RV64 JIT currently does not perform sign-extension for such kfunc args.

Before commit 7ce090afbf72 ("bpf: Infer zext_dst based on static register liveness analysis"), state pruning could potentially omit zero-extension of 32-bit subregisters, which inadvertently masked the above issue by making the args appear as if they had been properly sign-extended. After that commit, the problem is exposed, causing the kfunc_call/kfunc_call_test4 selftest to fail.

Leer descripción completaMostrar menos

Fix this by extending the existing sign-extension logic to handle signed 1-byte and 2-byte kfunc args as well.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90195",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "443574b033876c85a35de4c65c14f7fe092222b2",
              "lessThan": "555fc6f1caf00ce7005e732b688da26c0dc3c5c5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "443574b033876c85a35de4c65c14f7fe092222b2",
              "lessThan": "801ae90f8ce099187e6224cec7d72d07a4df0324",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "443574b033876c85a35de4c65c14f7fe092222b2",
              "lessThan": "71dbd143be598954ae103feadd12692aeb0f2f88",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "443574b033876c85a35de4c65c14f7fe092222b2",
              "lessThan": "f2aaa621591093cfe8224a25ef2f04a3b1e304b0",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/riscv/net/bpf_jit_comp64.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/riscv/net/bpf_jit_comp64.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:14.280",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/555fc6f1caf00ce7005e732b688da26c0dc3c5c5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/71dbd143be598954ae103feadd12692aeb0f2f88",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/801ae90f8ce099187e6224cec7d72d07a4df0324",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f2aaa621591093cfe8224a25ef2f04a3b1e304b0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv, bpf: Fix missing sign-ext for signed 1-byte and 2-byte kfunc args\n\nOn RV64, the ABI requires sign-extension for signed 1-byte and 2-byte kfunc\nargs. However, the RV64 JIT currently does not perform sign-extension for\nsuch kfunc args.\n\nBefore commit 7ce090afbf72 (\"bpf: Infer zext_dst based on static register\nliveness analysis\"), state pruning could potentially omit zero-extension\nof 32-bit subregisters, which inadvertently masked the above issue by making\nthe args appear as if they had been properly sign-extended. After that\ncommit, the problem is exposed, causing the kfunc_call/kfunc_call_test4\nselftest to fail.\n\nFix this by extending the existing sign-extension logic to handle signed\n1-byte and 2-byte kfunc args as well."
    }
  ],
  "lastModified": "2026-09-17T17:17:14.280",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}