CVE-2026-53078
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops
When a BPF sock_ops program accesses ctx fields with dst_reg == src_reg, the SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros fail to zero the destination register in the !fullsock / !locked_tcp_sock path.
Both macros borrow a temporary register to check is_fullsock / is_locked_tcp_sock when dst_reg == src_reg, because dst_reg holds the ctx pointer. When the check is false (e.g., TCP_NEW_SYN_RECV state with a request_sock), dst_reg should be zeroed but is not, leaving the stale ctx pointer:
Detalles técnicos trazas, registros y código del informe original
- SOCK_OPS_GET_SK: dst_reg retains the ctx pointer, passes NULL checks as PTR_TO_SOCKET_OR_NULL, and can be used as a bogus socket pointer, leading to stack-out-of-bounds access in helpers like bpf_skc_to_tcp6_sock(). - SOCK_OPS_GET_FIELD: dst_reg retains the ctx pointer which the verifier believes is a SCALAR_VALUE, leaking a kernel pointer. Fix both macros by: - Changing JMP_A(1) to JMP_A(2) in the fullsock path to skip the added instruction. - Adding BPF_MOV64_IMM(si->dst_reg, 0) after the temp register restore in the !fullsock path, placed after the restore because dst_reg == src_reg means we need src_reg intact to read ctx->temp.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1005Data from Local Systemcollection80 % - Impacto secundario
T1059Command and Scripting Interpreterexecution70 % - Impacto secundario
T1552.007Container APIcredential access75 %
Escalada local (AV:L/PR:L) permitiendo lectura OOB de memoria y fuga de punteros kernel; acceso local con privilegios de usuario.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-125
Referencias
- https://git.kernel.org/stable/c/0e6b30657bbc771f38025c828d722b6162428508
- https://git.kernel.org/stable/c/10f86a2a5c91fc4c4d001960f1c21abe52545ef6
- https://git.kernel.org/stable/c/18e3ffde1822f0b48b1753bf34aa97ce839df1d8
- https://git.kernel.org/stable/c/22400725de070b787cd6d806c5795370ab46d269
- https://git.kernel.org/stable/c/2a2c98141e0a75f2d4a7d78b0316c88b3da784ac
- https://git.kernel.org/stable/c/4c1c5efd9d1d74743d41ce4e1600501b4feb6827
- https://git.kernel.org/stable/c/64eaf4ecda007140ddcdb28e00c48c9c69aaba39
- https://git.kernel.org/stable/c/db1200ec2c3ddf119d4d9ba67982063df06bbacb
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-53078",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "fd09af010788a884de1c39537c288830c3d305db",
"lessThan": "db1200ec2c3ddf119d4d9ba67982063df06bbacb",
"versionType": "git"
},
{
"status": "affected",
"version": "fd09af010788a884de1c39537c288830c3d305db",
"lessThan": "4c1c5efd9d1d74743d41ce4e1600501b4feb6827",
"versionType": "git"
},
{
"status": "affected",
"version": "fd09af010788a884de1c39537c288830c3d305db",
"lessThan": "0e6b30657bbc771f38025c828d722b6162428508",
"versionType": "git"
},
{
"status": "affected",
"version": "fd09af010788a884de1c39537c288830c3d305db",
"lessThan": "64eaf4ecda007140ddcdb28e00c48c9c69aaba39",
"versionType": "git"
},
{
"status": "affected",
"version": "fd09af010788a884de1c39537c288830c3d305db",
"lessThan": "2a2c98141e0a75f2d4a7d78b0316c88b3da784ac",
"versionType": "git"
},
{
"status": "affected",
"version": "fd09af010788a884de1c39537c288830c3d305db",
"lessThan": "22400725de070b787cd6d806c5795370ab46d269",
"versionType": "git"
},
{
"status": "affected",
"version": "fd09af010788a884de1c39537c288830c3d305db",
"lessThan": "18e3ffde1822f0b48b1753bf34aa97ce839df1d8",
"versionType": "git"
},
{
"status": "affected",
"version": "fd09af010788a884de1c39537c288830c3d305db",
"lessThan": "10f86a2a5c91fc4c4d001960f1c21abe52545ef6",
"versionType": "git"
},
{
"status": "affected",
"version": "48be3df15aa19c04eadf156c9129293c9a10389f",
"versionType": "git"
},
{
"status": "affected",
"version": "cd4644d904e1d153d516e73e2e127e7a2fe687e1",
"versionType": "git"
},
{
"status": "affected",
"version": "6e0bc946cbeec538322820786b5fb5200a2216ab",
"versionType": "git"
},
{
"status": "affected",
"version": "a7e52f7f675046d9ffc5692d815fa67c82fcdbf5",
"versionType": "git"
},
{
"status": "affected",
"version": "db7f8c57dbdd31f7e59f8dc8d1e1b38607a320ef",
"versionType": "git"
},
{
"status": "affected",
"version": "5.7.18",
"lessThan": "5.8",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.8.4",
"lessThan": "5.9",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.4.61",
"lessThan": "5.5",
"versionType": "semver"
}
],
"programFiles": [
"net/core/filter.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.9",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/core/filter.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-06-24T17:17:21.850",
"references": [
{
"url": "https://git.kernel.org/stable/c/0e6b30657bbc771f38025c828d722b6162428508",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/10f86a2a5c91fc4c4d001960f1c21abe52545ef6",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/18e3ffde1822f0b48b1753bf34aa97ce839df1d8",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/22400725de070b787cd6d806c5795370ab46d269",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2a2c98141e0a75f2d4a7d78b0316c88b3da784ac",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4c1c5efd9d1d74743d41ce4e1600501b4feb6827",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/64eaf4ecda007140ddcdb28e00c48c9c69aaba39",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/db1200ec2c3ddf119d4d9ba67982063df06bbacb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix same-register dst/src OOB read and pointer leak in sock_ops\n\nWhen a BPF sock_ops program accesses ctx fields with dst_reg == src_reg,\nthe SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros fail to zero the\ndestination register in the !fullsock / !locked_tcp_sock path.\n\nBoth macros borrow a temporary register to check is_fullsock /\nis_locked_tcp_sock when dst_reg == src_reg, because dst_reg holds the\nctx pointer. When the check is false (e.g., TCP_NEW_SYN_RECV state with\na request_sock), dst_reg should be zeroed but is not, leaving the stale\nctx pointer:\n\n - SOCK_OPS_GET_SK: dst_reg retains the ctx pointer, passes NULL checks\n as PTR_TO_SOCKET_OR_NULL, and can be used as a bogus socket pointer,\n leading to stack-out-of-bounds access in helpers like\n bpf_skc_to_tcp6_sock().\n\n - SOCK_OPS_GET_FIELD: dst_reg retains the ctx pointer which the\n verifier believes is a SCALAR_VALUE, leaking a kernel pointer.\n\nFix both macros by:\n - Changing JMP_A(1) to JMP_A(2) in the fullsock path to skip the\n added instruction.\n - Adding BPF_MOV64_IMM(si->dst_reg, 0) after the temp register\n restore in the !fullsock path, placed after the restore because\n dst_reg == src_reg means we need src_reg intact to read ctx->temp."
}
],
"lastModified": "2026-09-14T12:17:43.033",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "435DC924-B527-4D24-9771-05EBDC20047B",
"versionEndExcluding": "5.5",
"versionStartIncluding": "5.4.61"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8141C666-AECC-41B8-BD7E-DED92216B4A5",
"versionEndExcluding": "5.8",
"versionStartIncluding": "5.7.18"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "560FB3D4-80AB-415C-96DA-0097E0BCB36F",
"versionEndExcluding": "5.9",
"versionStartIncluding": "5.8.4"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9211326E-7B68-49D5-BDEC-B2289D9A2F81",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "5.9.1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.9:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F79A2EB6-623E-4749-AEE0-DCB58C4C42F8"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.9:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A67F6509-9592-44D5-8C65-B0791C7A501A"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.9:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A52A4ABE-5C24-4CD4-A348-E303B7F23C71"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.9:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12019CF2-FD8E-4D59-BA4C-7093DF0BB091"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.9:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B1AB90E-C0C6-4027-B27D-BA214BE33561"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.9:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "103FE5BA-7315-4263-9C95-EABEAD7E174F"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.9:rc7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "47E31D6A-31EC-4F63-9CAE-B7A52B58E149"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.9:rc8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3497462B-A3DA-47CC-A5DD-C1C2D2E6DFDE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}