« Volver al listado

CVE-2026-74382

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_bpf: prevent unbounded recursion in offload rollback

Quan Sun reported [1] a stack overflow in cls_bpf_offload_cmd().

Reproducer on netdevsim: add a skip_sw cls_bpf filter, set the bpf_tc_accept debugfs knob to 0, then `tc filter replace`. The replace calls tc_setup_cb_replace() which fails. cls_bpf_offload_cmd() then swaps prog/oldprog and recursively calls itself to roll back. But bpf_tc_accept=0 makes the rollback fail too, which triggers yet another rollback frame with the same arguments, and so on until the stack is exhausted.

Leer descripción completaMostrar menos

bpf_tc_accept is just a convenient knob for the reproducer. Any driver whose tc_setup_cb_replace() fails twice in a row can hit the same loop, so this is not a netdevsim-only issue.

Two ways to fix it:

Go with (2). It is the smaller change and keeps the original behaviour: the rollback still goes through tc_setup_cb_replace(), so the driver gets one real chance to restore its state. If that attempt also fails, we just return the original error instead of recursing.

[1]: https://lore.kernel.org/bpf/ce5a6005-3c5e-4696-9e05-eba9461dc860@std.uestc.edu.cn/T/#u

Detalles técnicos trazas, registros y código del informe original
  1) Have the rollback call tc_setup_cb_add() on oldprog instead of
     re-entering cls_bpf_offload_cmd().
  2) Mark the rollback frame with a flag and skip a second-level
     rollback from inside it.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74382",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "102740bd9436a3a6ba129af3a48271d794009fa5",
              "lessThan": "a018f208ab7512380bd4cf670064d48cba00a1b1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "102740bd9436a3a6ba129af3a48271d794009fa5",
              "lessThan": "33373e1f378a501bc51aa73312f74295c84e3101",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "102740bd9436a3a6ba129af3a48271d794009fa5",
              "lessThan": "e2d3b7bab3748c811dc5750ce9a8d62bc7f90ed7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "102740bd9436a3a6ba129af3a48271d794009fa5",
              "lessThan": "4a76953c3ed043797e81529b9395e9ca6f4c7609",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "102740bd9436a3a6ba129af3a48271d794009fa5",
              "lessThan": "1387f252a242a51bfbb6eace29c8f8db21b457da",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "102740bd9436a3a6ba129af3a48271d794009fa5",
              "lessThan": "10753da2d659dd425a6e620f47f86852d604f67f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "102740bd9436a3a6ba129af3a48271d794009fa5",
              "lessThan": "3fa6fb5d771c992ebedbfa7331c6bcc6f33f89b7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "102740bd9436a3a6ba129af3a48271d794009fa5",
              "lessThan": "27db54b90bcc7c37867fe664107fa25ea6a116e4",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/sched/cls_bpf.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/sched/cls_bpf.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:40.040",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/10753da2d659dd425a6e620f47f86852d604f67f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1387f252a242a51bfbb6eace29c8f8db21b457da",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/27db54b90bcc7c37867fe664107fa25ea6a116e4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/33373e1f378a501bc51aa73312f74295c84e3101",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3fa6fb5d771c992ebedbfa7331c6bcc6f33f89b7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4a76953c3ed043797e81529b9395e9ca6f4c7609",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a018f208ab7512380bd4cf670064d48cba00a1b1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e2d3b7bab3748c811dc5750ce9a8d62bc7f90ed7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: cls_bpf: prevent unbounded recursion in offload rollback\n\nQuan Sun reported [1] a stack overflow in cls_bpf_offload_cmd().\n\nReproducer on netdevsim: add a skip_sw cls_bpf filter, set the\nbpf_tc_accept debugfs knob to 0, then `tc filter replace`. The replace\ncalls tc_setup_cb_replace() which fails. cls_bpf_offload_cmd() then\nswaps prog/oldprog and recursively calls itself to roll back. But\nbpf_tc_accept=0 makes the rollback fail too, which triggers yet another\nrollback frame with the same arguments, and so on until the stack is\nexhausted.\n\nbpf_tc_accept is just a convenient knob for the reproducer. Any driver\nwhose tc_setup_cb_replace() fails twice in a row can hit the same loop,\nso this is not a netdevsim-only issue.\n\nTwo ways to fix it:\n\n  1) Have the rollback call tc_setup_cb_add() on oldprog instead of\n     re-entering cls_bpf_offload_cmd().\n  2) Mark the rollback frame with a flag and skip a second-level\n     rollback from inside it.\n\nGo with (2). It is the smaller change and keeps the original behaviour:\nthe rollback still goes through tc_setup_cb_replace(), so the driver\ngets one real chance to restore its state. If that attempt also fails,\nwe just return the original error instead of recursing.\n\n[1]: https://lore.kernel.org/bpf/ce5a6005-3c5e-4696-9e05-eba9461dc860@std.uestc.edu.cn/T/#u"
    }
  ],
  "lastModified": "2026-08-17T06:19:33.073",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}