Database/Kernel, userspace & hypervisor
Linux kernel BPF uprobe_multi: unchecked __get_user on user-supplied data allows local memory disclosure or corruption
Impact
The uprobe_multi BPF link copied user-supplied data with __get_user without first validating the bounds with access_ok. A local process able to create a uprobe_multi link can hand the kernel an address it does not own, reading or writing memory outside the user range; on affected architectures this is a path from unprivileged-ish BPF access to kernel memory disclosure or corruption, and NVD rates it 7.8 local with high confidentiality, integrity and availability impact. On a GPU node this matters where BPF is reachable beyond root: eBPF-based observability agents, CNI dataplanes such as Cilium, and profiling sidecars are commonly granted CAP_BPF or CAP_SYS_ADMIN, so a compromised agent or a tenant workload holding those capabilities gets a kernel-level primitive on a host that also runs other tenants' GPU pods. It is local-only - there is no remote path - but a single node compromise on a shared GPU host means every pod resident on that node, and the node cannot be drained for free.
Who can reach it
Local authenticated user or container that can attach a uprobe_multi BPF link - in practice a process with CAP_BPF/CAP_SYS_ADMIN, or an unprivileged user on a kernel configured to permit BPF. No remote access.
What to do
Pick up the fixed stable kernel (the fix adds the missing access_ok check before __get_user); commits are in the kernel.org stable tree per the references. Applying it means a reboot of each node, so drain GPU workloads first - or defer by restricting BPF: tighten kernel.unprivileged_bpf_disabled and remove CAP_BPF/CAP_SYS_ADMIN from workloads that do not need tracing. No fixed release number is stated in the record beyond the listed stable commits.
References
Related entries
- Linux kernel mlx5_ib (queue pair sizing): set_rq_size() computes the receive-queue work-entry size as 1 << rq_wqe_shiftCVE-2026-74297 · Linux kernel mlx5_ib (queue pair sizing)High
- Linux kernel (drivers/vfio/pci/qat): Two concurrent writes to the QAT VF migration-resume file both pass the boundsCVE-2026-74306 · Linux kernel (drivers/vfio/pci/qat)High
- Linux kernel BPF: BPF_PROG_QUERY writes the revision field past a short bpf_attr from userspaceCVE-2026-74371 · Linux kernel BPF BPF_PROG_QUERY (cgroup query revision write-back)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDCVE-2026-74446 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeCVE-2026-74447 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel THP split: use-after-free on the inode when memory-failure splits a shmem huge pageCVE-2026-74482 · Linux kernel mm/huge_memory (__folio_split i_mmap_rwsem release order)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.