Database/Kernel, userspace & hypervisor
Linux kernel BPF verifier: ld_abs/ld_ind failure path left unverified inside subprograms
Impact
bpf_gen_ld_abs() emits an abnormal exit path (r0=0, return to caller) when the packet load fails, and the verifier never simulated it for subprogram uses. A program can therefore be accepted with a reachable path whose register state was never checked - the classic shape behind verifier-based local privilege escalation, and NVD scores it accordingly at 7.8 with full C/I/A. On a GPU fleet the loaders of BPF are usually privileged infrastructure (CNI dataplanes, tracing and security agents), so the practical exposure is workloads or sidecars that have been granted CAP_BPF, plus any host where unprivileged BPF is still permitted. It is not reachable from a plain tenant pod on a default modern distro configuration.
Who can reach it
Local user able to load a BPF program with ld_abs/ld_ind in a BTF-annotated subprogram - CAP_BPF (or CAP_SYS_ADMIN), or any local user on a host where kernel.unprivileged_bpf_disabled is 0.
What to do
Update to a stable kernel with the verifier fix and reboot the node. Until then, confirm kernel.unprivileged_bpf_disabled is set and audit which pods hold CAP_BPF - that bounds who can reach the verifier at all. Rolling reboots on GPU nodes require draining jobs, so pair this with other pending kernel fixes rather than opening a window for it alone.
References
Related entries
- Linux kernel BPF verifier: mis-tracked rX += rX delta lets a program diverge from its verified boundsCVE-2026-53092 · Linux kernel BPF verifier (linked-register delta tracking in adjust_reg_min_max_vals())High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeCVE-2026-53143 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel list_lru: cgroup teardown race lets two CPUs unlink the same list item under different locksCVE-2026-53153 · Linux kernel mm/list_lru (memcg reparenting on cgroup teardown)High
- Linux kernel (net/xfrm): Policy deletion dropped the policy lock before pruning the inexact-policy bin, and aCVE-2026-53239 · Linux kernel (net/xfrm)High
- Linux kernel IPv6: heap overwrite into skb_shared_info via UDPv6 MSG_MORE with MSG_SPLICE_PAGESCVE-2026-53362 · Linux kernel IPv6 (__ip6_append_data paged allocation path)High
- libvirt swtpm state handling: symlink following lets the swtpm user take ownership of arbitrary filesCVE-2026-63622 · libvirt (virFileChownFiles over the swtpm state directory)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.