Database/Kernel, userspace & hypervisor
Linux BPF verifier: kernel pointers leak through verifier logs for three pseudo ldimm64 sources
Impact
print_bpf_insn() masks rewritten pointer immediates when pointer leaks are disallowed, but the mask only covered BPF_PSEUDO_MAP_FD and BPF_PSEUDO_MAP_VALUE. BPF_PSEUDO_MAP_IDX, BPF_PSEUDO_MAP_IDX_VALUE and BPF_PSEUDO_BTF_ID are also rewritten to real kernel addresses before the log is printed, so a caller that can load a program and read the verifier log recovers kernel pointers it was explicitly supposed to be denied. That is a KASLR and heap-layout oracle, which matters on GPU nodes that run eBPF-based CNI, tracing and observability agents, and on any host where unprivileged or lightly privileged workloads can load BPF programs. It is an information leak only - no memory corruption - and the record publishes no CVSS score.
Who can reach it
Local user or container able to load a BPF program and read back the verifier log. Requires whatever BPF load capability the host policy grants (CAP_BPF or unprivileged BPF where enabled); hosts with kernel.unprivileged_bpf_disabled set reduce this to privileged callers.
What to do
Apply the stable-tree fix that adds the three pseudo sources to the pointer classification, then reboot the affected nodes. As an interim mitigation on fleets that cannot reboot immediately, confirm kernel.unprivileged_bpf_disabled=1 so only privileged workloads can reach the verifier log path. No fixed distribution version is named in the record.
References
Related entries
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeCVE-2026-74353 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Memory is handed to a consumer without beingCVE-2026-74448 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
- Linux kernel vhost: stale vring metadata cache lets a reconfigured vring access memory outside its IOTLB mappingCVE-2026-74580 · Linux kernel vhost (vring metadata IOTLB cache)Unscored
- Linux kernel BPF sockmap: use-after-free on the cached redirect socket in the send verdict pathCVE-2026-74589 · Linux kernel BPF sockmap (tcp_bpf_send_verdict sk_redir refcount)Unscored
- Linux kernel mm/filemap: page cache folio can be stored at the wrong index after an allocation retryCVE-2026-74591 · Linux kernel mm/filemap (__filemap_add_folio index restore on retry)Unscored
- Linux kernel IMA: truncation does not invalidate cached measurements, leaving stale appraisal stateCVE-2026-74592 · Linux kernel IMA (missing file_truncate / path_truncate LSM hooks)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.