Database/Kernel, userspace & hypervisor
Linux kernel bpf: arena 32-bit cmpxchg misses zero extension of the result register
Impact
is_cmpxchg_insn() matched only BPF_ATOMIC, so an atomic on an arena pointer - rewritten to BPF_PROBE_ATOMIC before the zext pass runs - did not get the explicit zero extension that BPF semantics require for a 32-bit cmpxchg. On architectures such as x86-64, where lock cmpxchg leaves the upper half of the destination register untouched on success, the program observes a register whose high bits are stale rather than zeroed. The record scores this as local availability impact only - no disclosure, no privilege gain is claimed - and reaching it requires loading a BPF program that uses arena atomics, which on a managed GPU node means holding CAP_BPF/CAP_SYS_ADMIN. It matters mainly where tenants or agents are permitted to load their own BPF: eBPF CNIs, tracing and observability agents on GPU hosts. Keep expectations low; this is a correctness fix, not a container escape.
Who can reach it
Local user or workload able to load a BPF program using arena atomics, which requires BPF load privilege (CAP_BPF or CAP_SYS_ADMIN) on the host. Not reachable from the network and not reachable by an unprivileged tenant pod that cannot load BPF.
What to do
Pick up a stable kernel containing the fix commits referenced below; the record names no single fixed release, so check your distribution's stream rather than assuming a version. Landing a kernel change on a GPU node means drain and reboot, and the GPU driver modules rebuild or reinstall against the new kernel - plan it with the normal kernel maintenance window rather than as an emergency. Where no window is available, restricting BPF load privilege removes the precondition.
References
Related entries
- Linux kernel BPF: tp_btf program dereferencing SEND_SIG_NOINFO can panic the nodeCVE-2026-98062 · Linux kernel BPF (signal_generate/signal_deliver raw tracepoint arguments)Medium
- Linux kernel nvmet-rdma: queue and IB resources leak when the connect backlog is exceededCVE-2026-98152 · Linux kernel nvmet-rdma (NVMe-oF RDMA target connect path)Medium
- AMD SEV-ES (CacheWarp): CacheWarp: INVD lets a malicious hypervisor revert SEV-ES guest memory writes, breaking guestCVE-2023-20592 · AMD SEV-ES (CacheWarp)Medium
- Linux kernel (drivers/pci): When the kernel coalesces two adjacent host-bridge apertures it invalidates the absorbedCVE-2023-53814 · Linux kernel (drivers/pci)Medium
- AMD SEV-SNP (BadRAM): BadRAM: improper validation of DIMM SPD metadata lets an attacker with physical access or ring0CVE-2024-21944 · AMD SEV-SNP (BadRAM)Medium
- OpenSSL QUIC: missing connection-level flow control lets a peer force ~100MB of heap per connectionCVE-2026-75804 · OpenSSL QUIC stack (connection-level flow control)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.