CVE-2026-80675
In the Linux kernel, the following vulnerability has been resolved:
libbpf: Reject non-exclusive metadata maps in the signed loader
The loader verifies map->sha against the metadata hash in its instructions. map->sha is calculated when BPF_OBJ_GET_INFO_BY_FD is called on the frozen map.
While the map is frozen, the /signed loader/ must also ensure the map is exclusive, as, without exclusivity (which a hostile host could just omit when loading the loader), another BPF program with map access can mutate the contents afterwards, so the check passes on stale data.
With the extra check as part of the signed loader, it now refuses to move on with map->sha validation if the host set it up wrongly.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1565.002Transmitted Data Manipulationimpact70 % - Impacto secundario
T1083File and Directory Discoverydiscovery60 %
Acceso local (AV:L) con privilegios de usuario (PR:L) en kernel Linux. La vulnerabilidad permite eludir validación de integridad de mapas BPF congelados (map->sha), permitiendo mutación de datos post-validación sin exclusividad verificada, dando capacidad de manipulación de datos de kernel.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80675",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "fb2b0e290147ba01a53dfd92cf91058c9d2ee254",
"lessThan": "b6862b6a25c6a925fb0b0e549ee4a52a8d2966fb",
"versionType": "git"
},
{
"status": "affected",
"version": "fb2b0e290147ba01a53dfd92cf91058c9d2ee254",
"lessThan": "0dad5adeb34b6f78a883e8faa6a1c947a240e7c9",
"versionType": "git"
},
{
"status": "affected",
"version": "fb2b0e290147ba01a53dfd92cf91058c9d2ee254",
"lessThan": "0fb6c9ed6493b4af01be8bb0a384574eba7df636",
"versionType": "git"
}
],
"programFiles": [
"include/linux/bpf.h",
"kernel/bpf/syscall.c",
"tools/lib/bpf/gen_loader.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.18"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.18",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"include/linux/bpf.h",
"kernel/bpf/syscall.c",
"tools/lib/bpf/gen_loader.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-28T08:16:52.793",
"references": [
{
"url": "https://git.kernel.org/stable/c/0dad5adeb34b6f78a883e8faa6a1c947a240e7c9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/0fb6c9ed6493b4af01be8bb0a384574eba7df636",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b6862b6a25c6a925fb0b0e549ee4a52a8d2966fb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibbpf: Reject non-exclusive metadata maps in the signed loader\n\nThe loader verifies map->sha against the metadata hash in its\ninstructions. map->sha is calculated when BPF_OBJ_GET_INFO_BY_FD is\ncalled on the frozen map.\n\nWhile the map is frozen, the /signed loader/ must also ensure the map\nis exclusive, as, without exclusivity (which a hostile host could just\nomit when loading the loader), another BPF program with map access can\nmutate the contents afterwards, so the check passes on stale data.\n\nWith the extra check as part of the signed loader, it now refuses to\nmove on with map->sha validation if the host set it up wrongly."
}
],
"lastModified": "2026-08-29T07:16:49.960",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}