« Volver al listado

CVE-2026-97420

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

bpf: NUL-terminate replaced sysctl value

When writing to sysctls, proc_sys_call_handler() guarantees that the buffer passed to proc handlers is NUL-terminated. If bpf_sysctl_set_new_value() replaces the pending sysctl value, it can hand a replacement buffer directly to proc handlers. However, the helper currently copies only buf_len bytes into that buffer without appending a NUL terminator, leaving downstream parsers vulnerable to out-of-bounds access.

Fix this by appending a '\0' after the replaced value to restore the expected sysctl semantics. Since the helper already rejects buf_len greater than PAGE_SIZE - 1, there is always room for the extra byte.

Leer descripción completaMostrar menos

Reproduced in a QEMU x86_64 guest booted with KASAN while exercising the sysctl replacement path with a cgroup/sysctl BPF program. The reproducer targets `/proc/sys/net/core/flow_limit_cpu_bitmap`, fills the original user write buffer with non-zero bytes, and overrides the sysctl value so the replacement buffer lacks a terminating NUL. Under that setup, the pre-fix kernel reported:

Detalles técnicos trazas, registros y código del informe original
  BUG: KASAN: slab-out-of-bounds in strnchrnul+0x72/0x90
  Read of size 1 at addr ffff88800de57000 by task repro_patch3/66
  CPU: 0 UID: 0 PID: 66 Comm: repro_patch3 Not tainted 7.1.0-rc3-00269-g8370ca1f87cc #6 PREEMPT(lazy)
  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
  Call Trace:
   <TASK>
   dump_stack_lvl+0x68/0xa0
   print_report+0xcb/0x5e0
   ? __virt_addr_valid+0x21d/0x3f0
   ? strnchrnul+0x72/0x90
   ? strnchrnul+0x72/0x90
   kasan_report+0xca/0x100
   ? strnchrnul+0x72/0x90
   strnchrnul+0x72/0x90
   bitmap_parse+0x37/0x2e0
   flow_limit_cpu_sysctl+0xc6/0x840
   ? __pfx_flow_limit_cpu_sysctl+0x10/0x10
   ? __kvmalloc_node_noprof+0x5ba/0x870
   proc_sys_call_handler+0x31d/0x480
   ? __pfx_proc_sys_call_handler+0x10/0x10
   ? selinux_file_permission+0x39f/0x500
   ? lock_is_held_type+0x9e/0x120
   vfs_write+0x98e/0x1000
   ...
   </TASK>
  The buggy address is located 0 bytes to the right of
  allocated 4096-byte region [ffff88800de56000, ffff88800de57000)
With this fix applied, rerunning the same sysctl-targeted path yields
no corresponding KASAN reports.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97420",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "32927393dc1ccd60fb2bdc05b9e8e88753761469",
              "lessThan": "bfcee1f79aaefa90679ad47690107fb7682724ec",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "32927393dc1ccd60fb2bdc05b9e8e88753761469",
              "lessThan": "c73e4a04eedc677fe91a736d7a5db45100adba5e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "32927393dc1ccd60fb2bdc05b9e8e88753761469",
              "lessThan": "36d3e9f62dc2beb9299d3bb6f589cb9e07f773fe",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "32927393dc1ccd60fb2bdc05b9e8e88753761469",
              "lessThan": "31377675c3d75603d957c08e338a9ac27e9f6cd5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "32927393dc1ccd60fb2bdc05b9e8e88753761469",
              "lessThan": "76c14b10f50eb0afcc76e244562fa2d8c661e224",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "32927393dc1ccd60fb2bdc05b9e8e88753761469",
              "lessThan": "3b2814dd842a565fcf9cc370156e1ba9eae16239",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "32927393dc1ccd60fb2bdc05b9e8e88753761469",
              "lessThan": "a66e3b5bacf38d6ab29fa05a9754f7a114485605",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/bpf/cgroup.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.8"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.8",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/bpf/cgroup.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T17:17:19.853",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/31377675c3d75603d957c08e338a9ac27e9f6cd5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/36d3e9f62dc2beb9299d3bb6f589cb9e07f773fe",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3b2814dd842a565fcf9cc370156e1ba9eae16239",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/76c14b10f50eb0afcc76e244562fa2d8c661e224",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a66e3b5bacf38d6ab29fa05a9754f7a114485605",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bfcee1f79aaefa90679ad47690107fb7682724ec",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c73e4a04eedc677fe91a736d7a5db45100adba5e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: NUL-terminate replaced sysctl value\n\nWhen writing to sysctls, proc_sys_call_handler() guarantees that the\nbuffer passed to proc handlers is NUL-terminated. If\nbpf_sysctl_set_new_value() replaces the pending sysctl value, it can\nhand a replacement buffer directly to proc handlers. However, the\nhelper currently copies only buf_len bytes into that buffer without\nappending a NUL terminator, leaving downstream parsers vulnerable to\nout-of-bounds access.\n\nFix this by appending a '\\0' after the replaced value to restore the\nexpected sysctl semantics. Since the helper already rejects buf_len\ngreater than PAGE_SIZE - 1, there is always room for the extra byte.\n\nReproduced in a QEMU x86_64 guest booted with KASAN while exercising\nthe sysctl replacement path with a cgroup/sysctl BPF program. The\nreproducer targets `/proc/sys/net/core/flow_limit_cpu_bitmap`, fills\nthe original user write buffer with non-zero bytes, and overrides the\nsysctl value so the replacement buffer lacks a terminating NUL. Under\nthat setup, the pre-fix kernel reported:\n\n  BUG: KASAN: slab-out-of-bounds in strnchrnul+0x72/0x90\n  Read of size 1 at addr ffff88800de57000 by task repro_patch3/66\n  CPU: 0 UID: 0 PID: 66 Comm: repro_patch3 Not tainted 7.1.0-rc3-00269-g8370ca1f87cc #6 PREEMPT(lazy)\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x68/0xa0\n   print_report+0xcb/0x5e0\n   ? __virt_addr_valid+0x21d/0x3f0\n   ? strnchrnul+0x72/0x90\n   ? strnchrnul+0x72/0x90\n   kasan_report+0xca/0x100\n   ? strnchrnul+0x72/0x90\n   strnchrnul+0x72/0x90\n   bitmap_parse+0x37/0x2e0\n   flow_limit_cpu_sysctl+0xc6/0x840\n   ? __pfx_flow_limit_cpu_sysctl+0x10/0x10\n   ? __kvmalloc_node_noprof+0x5ba/0x870\n   proc_sys_call_handler+0x31d/0x480\n   ? __pfx_proc_sys_call_handler+0x10/0x10\n   ? selinux_file_permission+0x39f/0x500\n   ? lock_is_held_type+0x9e/0x120\n   vfs_write+0x98e/0x1000\n   ...\n   </TASK>\n  The buggy address is located 0 bytes to the right of\n  allocated 4096-byte region [ffff88800de56000, ffff88800de57000)\nWith this fix applied, rerunning the same sysctl-targeted path yields\nno corresponding KASAN reports."
    }
  ],
  "lastModified": "2026-10-03T11:17:54.123",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}