GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel bpf: arena 32-bit cmpxchg misses zero extension of the result register

CVSS 5.5CVE-2026-98049Kernel, userspace & hypervisorcurated

Impact

is_cmpxchg_insn() matched only BPF_ATOMIC, so an atomic on an arena pointer - rewritten to BPF_PROBE_ATOMIC before the zext pass runs - did not get the explicit zero extension that BPF semantics require for a 32-bit cmpxchg. On architectures such as x86-64, where lock cmpxchg leaves the upper half of the destination register untouched on success, the program observes a register whose high bits are stale rather than zeroed. The record scores this as local availability impact only - no disclosure, no privilege gain is claimed - and reaching it requires loading a BPF program that uses arena atomics, which on a managed GPU node means holding CAP_BPF/CAP_SYS_ADMIN. It matters mainly where tenants or agents are permitted to load their own BPF: eBPF CNIs, tracing and observability agents on GPU hosts. Keep expectations low; this is a correctness fix, not a container escape.

Who can reach it

Local user or workload able to load a BPF program using arena atomics, which requires BPF load privilege (CAP_BPF or CAP_SYS_ADMIN) on the host. Not reachable from the network and not reachable by an unprivileged tenant pod that cannot load BPF.

What to do

Pick up a stable kernel containing the fix commits referenced below; the record names no single fixed release, so check your distribution's stream rather than assuming a version. Landing a kernel change on a GPU node means drain and reboot, and the GPU driver modules rebuild or reinstall against the new kernel - plan it with the normal kernel maintenance window rather than as an emergency. Where no window is available, restricting BPF load privilege removes the precondition.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.