Database/Kernel, userspace & hypervisor
Linux kernel BPF verifier: commuted pointer arithmetic loses pointer provenance state
Impact
When the verifier handles scalar += pointer, the destination register inherits only selected fields of the source pointer state, while provenance is actually tracked across several bpf_reg_state fields - the frame number for PTR_TO_STACK and the parent identity fields among them. The fix replaces the destination with the full pointer state instead of copying pieces. The record describes fragile state tracking, not a demonstrated sandbox escape, and gives no CVSS or CWE; treat it as a verifier hardening fix whose worst case is mis-tracked pointer state. It matters on a shared fleet because verifier state bugs are the usual route from BPF program loading to kernel memory access.
Who can reach it
Anyone able to load a BPF program. On a default fleet that means root or CAP_BPF - unprivileged BPF is disabled by default - so the realistic loaders are the CNI, observability agents and node tooling. On hosts where unprivileged BPF has been re-enabled, any local user including a tenant pod.
What to do
Update to a stable kernel with the fix and reboot at the next kernel roll. In the meantime, confirm kernel.unprivileged_bpf_disabled is set and audit which workloads hold CAP_BPF - that is a sysctl and a policy check, not a drain, and it bounds who can reach the verifier at all.
References
Related entries
- Linux kernel sched_ext: a failed sub-scheduler enable races root disable into a use-after-freeCVE-2026-74731 · Linux kernel sched_ext (scx_sub_disable teardown of never-linked sub-schedulers)Unscored
- Linux kernel perf/core: exited event accepted as group leader leaves a sibling pointing at freed memoryCVE-2026-74753 · Linux kernel perf/core (perf_event_open group-leader state validation)Unscored
- Xen: guest with a passthrough PCI device exposing an IO port BAR can trigger a hypervisor BUG()CVE-2026-79602 · Xen hypervisor (PCI passthrough, IO port BAR handling)Unscored
- libcurl: pooled TLS connection outlives its easy handle and reuses a freed OpenSSL library contextCVE-2026-80229 · libcurl (multi interface, OpenSSL 3 provider library context)Unscored
- Linux kernel CephFS client: readers hang indefinitely after cap revocation leaves stale mds_wantedCVE-2026-80527 · Linux kernel CephFS client (__ceph_get_caps / ceph_renew_caps, stale cap->mds_wanted)Unscored
- Linux kernel CephFS client: reclaim during MDS reply handling crashes the kernel via ext4 journal_infoCVE-2026-80528 · Linux kernel CephFS client (handle_reply / current->journal_info vs direct reclaim)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.