« Volver al listado

CVE-2026-92515

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

bpf: Preserve unique-field state across nested structs

btf_find_struct_field() initializes a fresh seen mask for every recursive descent. Unique special fields in different levels of the same aggregate therefore do not see one another. The duplicate fields can reach btf_parse_fields(), where they trigger an invariant WARN_ON_ONCE(). A crafted user BTF can consequently trigger the warning before map creation checks capabilities.

Initialize the seen mask once in btf_find_field() and pass the same pointer through struct, datasec, and nested-struct walks. This gives the entire field traversal one shared uniqueness state.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-92515",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "64e8ee814819f21beeeda00d4119221443d77992",
              "lessThan": "cec97102d4147e18568c93946014c4c8ebf86fcf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "64e8ee814819f21beeeda00d4119221443d77992",
              "lessThan": "28d5f20ed022ade0fb0bfbf50b78fec782083175",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "64e8ee814819f21beeeda00d4119221443d77992",
              "lessThan": "373a1e9366e711b89bc5e45bd6edf33ef62402cd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "64e8ee814819f21beeeda00d4119221443d77992",
              "lessThan": "f08619f060468076e4acbdc10e0713af20d60e65",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/bpf/btf.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/bpf/btf.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:54.360",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/28d5f20ed022ade0fb0bfbf50b78fec782083175",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/373a1e9366e711b89bc5e45bd6edf33ef62402cd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cec97102d4147e18568c93946014c4c8ebf86fcf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f08619f060468076e4acbdc10e0713af20d60e65",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Preserve unique-field state across nested structs\n\nbtf_find_struct_field() initializes a fresh seen mask for every recursive\ndescent. Unique special fields in different levels of the same aggregate\ntherefore do not see one another. The duplicate fields can reach\nbtf_parse_fields(), where they trigger an invariant WARN_ON_ONCE(). A\ncrafted user BTF can consequently trigger the warning before map creation\nchecks capabilities.\n\nInitialize the seen mask once in btf_find_field() and pass the same pointer\nthrough struct, datasec, and nested-struct walks. This gives the entire field\ntraversal one shared uniqueness state."
    }
  ],
  "lastModified": "2026-09-17T17:17:54.360",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}