« Volver al listado

CVE-2026-90359

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject >8 byte return values on return-reading trampoline paths

btf_distill_func_proto() builds the function model used for the fentry/fexit/fmod_ret/fsession trampolines and struct_ops. It has accepted a 16-byte __int128 return value since the trampoline was introduced: __get_type_size() returns the integer's type size, and the return-type check only rejected ret < 0.

But the BPF trampoline preserves only 8 bytes of the return value (RAX on x86, i.e. R0).

Leer descripción completaMostrar menos

For an attach type that reads the target's return value the second half (RDX / R3) is neither saved nor restored, so a program attached to a function returning a 16-byte value corrupts the value seen by the real caller and itself observes only half of it. struct_ops trampolines have the same limitation.

This affects the attach types that read the target's return value: fexit, fmod_ret and fsession (plus the _multi variants of fexit and fsession), and struct_ops. fentry/fentry_multi run before the target returns and are unaffected.

Reject a >8 byte return value for these attach types in bpf_check_attach_target() and bpf_check_attach_btf_id_multi(), and for struct_ops in bpf_struct_ops_desc_init().

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90359",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "fec56f5890d93fc2ed74166c397dc186b1c25951",
              "lessThan": "d36ac53fc83baf843c51b7afd6d2471f36b713d8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fec56f5890d93fc2ed74166c397dc186b1c25951",
              "lessThan": "c48796aa6c392cde93946e5d5a9a1f1b1cf72feb",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/bpf/bpf_struct_ops.c",
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.5"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.5",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/bpf/bpf_struct_ops.c",
            "kernel/bpf/verifier.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:34.810",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/c48796aa6c392cde93946e5d5a9a1f1b1cf72feb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d36ac53fc83baf843c51b7afd6d2471f36b713d8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject >8 byte return values on return-reading trampoline paths\n\nbtf_distill_func_proto() builds the function model used for the\nfentry/fexit/fmod_ret/fsession trampolines and struct_ops. It has\naccepted a 16-byte __int128 return value since the trampoline was\nintroduced: __get_type_size() returns the integer's type size, and the\nreturn-type check only rejected ret < 0.\n\nBut the BPF trampoline preserves only 8 bytes of the return value (RAX on\nx86, i.e. R0). For an attach type that reads the target's return value the\nsecond half (RDX / R3) is neither saved nor restored, so a program\nattached to a function returning a 16-byte value corrupts the value seen\nby the real caller and itself observes only half of it. struct_ops\ntrampolines have the same limitation.\n\nThis affects the attach types that read the target's return value: fexit,\nfmod_ret and fsession (plus the _multi variants of fexit and fsession),\nand struct_ops. fentry/fentry_multi run before the target returns and are\nunaffected.\n\nReject a >8 byte return value for these attach types in\nbpf_check_attach_target() and bpf_check_attach_btf_id_multi(), and for\nstruct_ops in bpf_struct_ops_desc_init()."
    }
  ],
  "lastModified": "2026-09-17T17:17:34.810",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}