Database/Kernel, userspace & hypervisor
Linux kernel x86/kprobes: wrong return address when probing a CS-prefixed CALL crashes the host
Impact
int3_emulate_call() assumes a probed CALL is 5 bytes, but a CS-prefixed CALL (emitted for indirect-thunk retpoline sites) is 6 bytes, so single-step emulation builds a return address in the middle of the instruction. The CPU then decodes garbage and the kernel oopses - the report shows a page fault in __hrtimer_run_queues(). Anyone able to place a kprobe or eBPF kprobe at an arbitrary function offset can crash the host, and on a GPU node that drops every tenant on the box. This matters most where observability agents or privileged debugging tooling attach kprobes by offset on fleet nodes.
Who can reach it
Local user with kprobe/eBPF tracing privileges (CAP_BPF/CAP_PERFMON or root, or an unconfined observability agent). Not reachable by an unprivileged tenant pod without tracing capabilities.
What to do
Apply the stable fix that uses the decoded instruction length instead of CALL_INSN_SIZE. Kernel update and node reboot, so drain first. In the meantime, do not grant kprobe/eBPF tracing capabilities to tenant workloads and avoid offset-based probes inside functions on affected kernels. No CVSS score or distro advisory in the record.
References
Related entries
- powerpc/iommu: TCE IOBA range check ignores npages, allowing out-of-range table accessCVE-2026-98282 · Linux kernel powerpc/iommu (iommu_tce_check_ioba npages validation)Unscored
- KVM PPC Book3S HV: use-after-free on nested guest struct during all-LPID tlbie emulationCVE-2026-98283 · Linux kernel KVM PPC Book3S HV (kvmhv_emulate_tlbie_all_lpid)Unscored
- Microsoft Hyper-V: vmswitch fails to validate guest OID requestsCVE-2021-28476 · Microsoft Hyper-VCritical
- Incus: instance snapshots bypass restricted.containers.lowlevel, giving command execution on the hostCVE-2026-48751 · Incus (instance snapshots ignore restricted.containers.lowlevel)Critical
- VMware ESXi (OpenSLP): Use-after-free in OpenSLP on port 427 - unauthenticated remote code execution on the hypervisorCVE-2020-3992 · VMware ESXi (OpenSLP)Critical
- Linux kernel mlx5_core kTLS RX offload: TLS RX resync list corruption: entries are moved by the resync handlerCVE-2021-47215 · Linux kernel mlx5_core kTLS RX offloadCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.