GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel BPF: sysctl value replaced by a BPF program is not NUL-terminated, giving out-of-bounds reads

UnscoredCVE-2026-97420Kernel, userspace & hypervisorcurated

Impact

proc_sys_call_handler() guarantees that sysctl proc handlers receive a NUL-terminated buffer, but bpf_sysctl_set_new_value() copied only buf_len bytes into the replacement buffer it hands downstream, dropping the terminator. A sysctl parser that scans for the end of the string then reads past the allocation; the commit reproduces a KASAN slab-out-of-bounds in strnchrnul() via bitmap_parse() on /proc/sys/net/core/flow_limit_cpu_bitmap. Practical reach is narrow: an attacker must already be able to attach a cgroup/sysctl BPF program, which is a privileged operation. It matters on fleets that run BPF-based policy and networking agents on every node, because the corrupting path then exists in the always-loaded kernel surface rather than in an optional module.

Who can reach it

Local privileged user able to load and attach a cgroup/sysctl BPF program (CAP_BPF/CAP_SYS_ADMIN in the relevant namespace), combined with a write to an affected sysctl. Not reachable by an unprivileged tenant pod that cannot load BPF, and not network reachable.

What to do

Run a kernel carrying the one-line fix that appends '\0' after the replaced value; five stable backports are linked in the record. Rolling it out means a drain and reboot per node unless your distro ships it as a livepatch. No vendor advisory or fixed product version is present in the record.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.