GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux BPF verifier: kernel pointers leak through verifier logs for three pseudo ldimm64 sources

UnscoredCVE-2026-72402Kernel, userspace & hypervisorcurated

Impact

print_bpf_insn() masks rewritten pointer immediates when pointer leaks are disallowed, but the mask only covered BPF_PSEUDO_MAP_FD and BPF_PSEUDO_MAP_VALUE. BPF_PSEUDO_MAP_IDX, BPF_PSEUDO_MAP_IDX_VALUE and BPF_PSEUDO_BTF_ID are also rewritten to real kernel addresses before the log is printed, so a caller that can load a program and read the verifier log recovers kernel pointers it was explicitly supposed to be denied. That is a KASLR and heap-layout oracle, which matters on GPU nodes that run eBPF-based CNI, tracing and observability agents, and on any host where unprivileged or lightly privileged workloads can load BPF programs. It is an information leak only - no memory corruption - and the record publishes no CVSS score.

Who can reach it

Local user or container able to load a BPF program and read back the verifier log. Requires whatever BPF load capability the host policy grants (CAP_BPF or unprivileged BPF where enabled); hosts with kernel.unprivileged_bpf_disabled set reduce this to privileged callers.

What to do

Apply the stable-tree fix that adds the three pseudo sources to the pointer classification, then reboot the affected nodes. As an interim mitigation on fleets that cannot reboot immediately, confirm kernel.unprivileged_bpf_disabled=1 so only privileged workloads can reach the verifier log path. No fixed distribution version is named in the record.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.