CVE-2026-89581
In the Linux kernel, the following vulnerability has been resolved:
bpf, x86: Fix per-CPU address resolution into an extended register
The destination of the per-CPU address MOV is encoded in ModRM.reg, which is extended by REX.R, but the REX prefix is built with add_1mod(), which sets REX.B. REX.B extends ModRM.rm and SIB.base, and this instruction addresses memory as disp32 with no base, so the bit has no effect at all and the high register bit is simply lost.
Every is_ereg() destination therefore resolves to the wrong register, picking whichever one shares the low three bits:
With BPF_REG_5, whose reg2hex is 0, the emitted
Read full descriptionShow less
adds the per-CPU offset to RAX rather than R8. The destination keeps the unadjusted address and RAX is clobbered, so the program goes on to dereference a pointer that was never made per-CPU:
R5 is the mildest of the four, aliasing a scratch register and faulting at the store. R7 aliases RBP and would corrupt the frame pointer, R8 and R9 alias the argument registers.
Use add_2mod() so the register goes through REX.R, matching how add_2reg() places it in ModRM.reg and how emit_priv_frame_ptr() hardcodes 0x4c for the same instruction with R9. Encodings for the non-extended registers are unchanged.
Problem showed up when trying to resurrect BPF_GCC CI (selftests built with BPF_GCC).
This has gone unnoticed because clang reloads the address into R1 before each per-CPU access, so the destination is never an extended register. GCC keeps several per-CPU addresses live at once, and test_progs-bpf_gcc panics the kernel in global_percpu_data/init, where the address of a .percpu variable ends up in R5.
Technical details traces, logs and code from the original report
R5 -> RAX R7 -> RBP R8 -> RSI R9 -> RDI 65 49 03 04 25 <off> add %gs:<off>,%rax BUG: unable to handle page fault for address: 0000607e386a8894 RIP: bpf_prog_707837aafd2aa9ae_update_percpu_data+0x93/0xc9 Call Trace: __bpf_prog_test_run_raw_tp+0x2dc/0x7d0 __flush_smp_call_function_queue+0x1e9/0xc80 Kernel panic - not syncing: Fatal exception in interrupt
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Base score: 7.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.13%
- Percentile among all scored CVEs: 2
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Primary impact
T1499.004Application or System Exploitationimpact75 % - Secondary impact
T1565.001Stored Data Manipulationimpact65 %
Acceso local (AV:L) sin interacción de usuario, con privilegios normales (PR:L). Fallo en resolución de direcciones per-CPU en kernel permite corrupción de memoria y DoS por pánico del kernel, afectando integridad y disponibilidad del sistema.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-89581",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "7bdbf7446305cb65c510c16d57cde82bc76b234a",
"lessThan": "638bc3aada8ecdece184d5c15b100d489c9cccd7",
"versionType": "git"
},
{
"status": "affected",
"version": "7bdbf7446305cb65c510c16d57cde82bc76b234a",
"lessThan": "6886642414f59f928728802dc2c972a9859e6310",
"versionType": "git"
},
{
"status": "affected",
"version": "7bdbf7446305cb65c510c16d57cde82bc76b234a",
"lessThan": "6a19b18d458881bf3269a357cc6dc6db5eef4369",
"versionType": "git"
},
{
"status": "affected",
"version": "7bdbf7446305cb65c510c16d57cde82bc76b234a",
"lessThan": "5bbbce02e500d47d8e259a45be5a7be9741d0533",
"versionType": "git"
}
],
"programFiles": [
"arch/x86/net/bpf_jit_comp.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.10"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.10",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.109",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.50",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"arch/x86/net/bpf_jit_comp.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-11T20:19:42.397",
"references": [
{
"url": "https://git.kernel.org/stable/c/5bbbce02e500d47d8e259a45be5a7be9741d0533",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/638bc3aada8ecdece184d5c15b100d489c9cccd7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6886642414f59f928728802dc2c972a9859e6310",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6a19b18d458881bf3269a357cc6dc6db5eef4369",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, x86: Fix per-CPU address resolution into an extended register\n\nThe destination of the per-CPU address MOV is encoded in ModRM.reg,\nwhich is extended by REX.R, but the REX prefix is built with\nadd_1mod(), which sets REX.B. REX.B extends ModRM.rm and SIB.base, and\nthis instruction addresses memory as disp32 with no base, so the bit\nhas no effect at all and the high register bit is simply lost.\n\nEvery is_ereg() destination therefore resolves to the wrong register,\npicking whichever one shares the low three bits:\n\n R5 -> RAX R7 -> RBP R8 -> RSI R9 -> RDI\n\nWith BPF_REG_5, whose reg2hex is 0, the emitted\n\n 65 49 03 04 25 <off>\tadd %gs:<off>,%rax\n\nadds the per-CPU offset to RAX rather than R8. The destination keeps\nthe unadjusted address and RAX is clobbered, so the program goes on to\ndereference a pointer that was never made per-CPU:\n\n BUG: unable to handle page fault for address: 0000607e386a8894\n RIP: bpf_prog_707837aafd2aa9ae_update_percpu_data+0x93/0xc9\n Call Trace:\n __bpf_prog_test_run_raw_tp+0x2dc/0x7d0\n __flush_smp_call_function_queue+0x1e9/0xc80\n Kernel panic - not syncing: Fatal exception in interrupt\n\nR5 is the mildest of the four, aliasing a scratch register and faulting\nat the store. R7 aliases RBP and would corrupt the frame pointer, R8\nand R9 alias the argument registers.\n\nUse add_2mod() so the register goes through REX.R, matching how\nadd_2reg() places it in ModRM.reg and how emit_priv_frame_ptr()\nhardcodes 0x4c for the same instruction with R9. Encodings for the\nnon-extended registers are unchanged.\n\nProblem showed up when trying to resurrect BPF_GCC CI (selftests built\nwith BPF_GCC).\n\nThis has gone unnoticed because clang reloads the address into R1\nbefore each per-CPU access, so the destination is never an extended\nregister. GCC keeps several per-CPU addresses live at once, and\ntest_progs-bpf_gcc panics the kernel in global_percpu_data/init, where\nthe address of a .percpu variable ends up in R5."
}
],
"lastModified": "2026-09-13T07:17:23.853",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}