Database/Kernel, userspace & hypervisor
Linux kernel bpf: BPF_REFCOUNT field was not marked unique in the verifier's field checks
Impact
The verifier's record of special BTF fields did not mark BPF_REFCOUNT as unique, so a BPF type could declare more than one refcount field where the verifier's later reasoning assumes exactly one. On a GPU node the BPF machinery is what observability agents, CNI dataplanes and security agents load, and a verifier bookkeeping gap is a soundness question about that boundary. The upstream record is a one-line oversight fix with no exploit, no score and no described attack scenario, so treat the practical exposure as unestablished rather than as a demonstrated escalation. It is local-only in any case: loading a BPF program with a refcounted kptr field requires privilege, not tenant access.
Who can reach it
Local, and only for a caller that can load BPF programs - CAP_BPF plus CAP_SYS_ADMIN (or unprivileged BPF explicitly enabled). A tenant confined to a GPU pod without BPF capabilities cannot reach the path.
What to do
Pick up the fix from your distribution's stable kernel (three stable commits linked); it ships as a normal kernel update, so each node has to be drained and rebooted. In the meantime, keep BPF program loading restricted to the agents that need it - kernel.unprivileged_bpf_disabled and not granting CAP_BPF to workload pods.
References
Related entries
- Xen (EPT): Use-after-free of EPT paging structures - HVM guest to host compromiseCVE-2026-23554 · Xen (EPT)Unscored
- Xen (x86 HVM): x86 HVM I/O port list traversal flawCVE-2026-42487 · Xen (x86 HVM)Unscored
- FreeBSD ZFS: 64-to-32-bit size truncation in the heal receive path corrupts kernel memoryCVE-2026-49430 · FreeBSD ZFS ZFS_IOC_RECV_NEW ioctl (heal receive path)Unscored
- FreeBSD ZFS: unprivileged local user can set the internal $hasrecvd metadata flag on a datasetCVE-2026-49431 · FreeBSD ZFS ZFS_IOC_SET_PROP ioctl (zfs-set privilege check)Unscored
- Xen (grant tables): Type confusion in grant-copy - guest corrupts hypervisor stateCVE-2026-62428 · Xen (grant tables)Unscored
- Xen (grant tables): Grant-table version change racing with other operationsCVE-2026-62435 · Xen (grant tables)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.