Database/Kernel, userspace & hypervisor
Linux kernel BPF: sysctl value replaced by a BPF program is not NUL-terminated, giving out-of-bounds reads
Impact
proc_sys_call_handler() guarantees that sysctl proc handlers receive a NUL-terminated buffer, but bpf_sysctl_set_new_value() copied only buf_len bytes into the replacement buffer it hands downstream, dropping the terminator. A sysctl parser that scans for the end of the string then reads past the allocation; the commit reproduces a KASAN slab-out-of-bounds in strnchrnul() via bitmap_parse() on /proc/sys/net/core/flow_limit_cpu_bitmap. Practical reach is narrow: an attacker must already be able to attach a cgroup/sysctl BPF program, which is a privileged operation. It matters on fleets that run BPF-based policy and networking agents on every node, because the corrupting path then exists in the always-loaded kernel surface rather than in an optional module.
Who can reach it
Local privileged user able to load and attach a cgroup/sysctl BPF program (CAP_BPF/CAP_SYS_ADMIN in the relevant namespace), combined with a write to an affected sysctl. Not reachable by an unprivileged tenant pod that cannot load BPF, and not network reachable.
What to do
Run a kernel carrying the one-line fix that appends '\0' after the replaced value; five stable backports are linked in the record. Rolling it out means a drain and reboot per node unless your distro ships it as a livepatch. No vendor advisory or fixed product version is present in the record.
References
Related entries
- Linux kernel net/rds: unprivileged container reads every RDS socket and connection on the hostCVE-2026-97476 · Linux kernel net/rds RDS_INFO_* getsockopt (missing netns filtering)Unscored
- Linux kernel net/rds: RDS-over-IB shutdown sleeps in a shared worker and hangs fabric teardownCVE-2026-97491 · Linux kernel net/rds over InfiniBand (rds_ib_conn_path_shutdown sleeping in the shutdown worker)Unscored
- Linux PCI sysfs: BAR resize via resourceN_resize had no CAP_SYS_ADMIN checkCVE-2026-97505 · Linux kernel PCI sysfs (resourceN_resize, __resource_resize_store)Unscored
- Linux kernel qla2xxx: unvalidated FC BSG request length causes out-of-bounds heap readsCVE-2026-97529 · Linux kernel qla2xxx (FC BSG vendor command request_len validation)Unscored
- Linux kernel qla2xxx: FC frame payload aliasing 0xDEADDEAD spins the interrupt handler into a CPU soft lockupCVE-2026-97530 · Linux kernel qla2xxx (continuation IOCB signature poll in interrupt context)Unscored
- Linux qla2xxx: double free and NULL dma_pool use when adapter memory allocation fails at probeCVE-2026-97532 · Linux kernel scsi qla2xxx (qla2x00_mem_alloc error path, dangling pointers)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.