« Volver al listado

CVE-2026-89905

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

LoongArch: BPF: Move arena register slot below TCC context

Currently, the stack layout places the optional arena register slot above the tail call counter context. When arena_vm_start is dynamically enabled, it shifts the relative offset of the tcc_ptr slot within the stack frame, causing hardcoded tracking macros to mismatch and leading to memory misalignment or corruption potentially.

To fix this, move the arena register save and restore sequences below the tail call counter context slots in both build_prologue() and the epilogue.

Leer descripción completaMostrar menos

Update __build_epilogue() to insert a proper offset decrement to safely skip the unneeded tcc_ptr reading block while accurately aligning with the relocated arena slot at the very bottom.

With this patch, the tcc_ptr slot is always positioned at a fixed distance directly underneath the base callee-saved registers that is independent of whether the arena features are on.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89905",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ef54c517a9376b188da06b5e1ed556129c4280be",
              "lessThan": "f0e4d069cb47cf4f8dc4f6bc104e0671155aa3b9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ef54c517a9376b188da06b5e1ed556129c4280be",
              "lessThan": "cd7e356b07a27e91394838cf3fb655862b519294",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/loongarch/net/bpf_jit.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/loongarch/net/bpf_jit.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:16:59.483",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/cd7e356b07a27e91394838cf3fb655862b519294",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f0e4d069cb47cf4f8dc4f6bc104e0671155aa3b9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: BPF: Move arena register slot below TCC context\n\nCurrently, the stack layout places the optional arena register slot\nabove the tail call counter context. When arena_vm_start is dynamically\nenabled, it shifts the relative offset of the tcc_ptr slot within the\nstack frame, causing hardcoded tracking macros to mismatch and leading\nto memory misalignment or corruption potentially.\n\nTo fix this, move the arena register save and restore sequences below\nthe tail call counter context slots in both build_prologue() and the\nepilogue.\n\nUpdate __build_epilogue() to insert a proper offset decrement to safely\nskip the unneeded tcc_ptr reading block while accurately aligning with\nthe relocated arena slot at the very bottom.\n\nWith this patch, the tcc_ptr slot is always positioned at a fixed\ndistance directly underneath the base callee-saved registers that is\nindependent of whether the arena features are on."
    }
  ],
  "lastModified": "2026-09-16T11:16:59.483",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}