{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89579","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.728Z","datePublished":"2026-09-11T19:44:46.110Z","dateUpdated":"2026-09-14T12:01:09.673Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:01:09.673Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Harden bloom filter sizing and indexing on 32-bit kernels\n\nbloom_map_alloc() has two 32-bit-specific problems when the computed\nbitmap reaches the U32_MAX fallback case.\n\nFirst, BITS_TO_BYTES(U32_MAX) is evaluated with 32-bit arithmetic. The\naddition performed by DIV_ROUND_UP wraps, so the map allocates only the\nfixed-size bloom filter object while keeping bitset_mask == U32_MAX.\nSubsequent updates can then write past the allocated object.\n\nSecond, fixing only the allocation size is not sufficient. The bloom hash\nis a u32, but set_bit() takes a signed long bit number and x86 test_bit()\neventually feeds the index to variable_test_bit(long, ...). On 32-bit\nkernels, hashes in [0x80000000, U32_MAX] therefore become negative bit\noffsets. x86 bt/bts with a memory operand interpret those offsets relative\nto the supplied base, so a map with bitset_mask == U32_MAX can read or\nwrite before bloom->bitset even after allocating the full 512 MiB bitmap.\n\nKeep the U32_MAX fallback, but split each hash into a word pointer and an\nin-word bit number before calling test_bit() or set_bit(). The bitops\nargument is then always in [0, BITS_PER_LONG - 1], while BIT_WORD(h) still\nselects the intended word in the full bitmap.\n\nCompute the bitset size from (u64)bitset_mask + 1 before passing the final\nsize to bpf_map_area_alloc(). This fixes the original under-allocation and\nkeeps the allocated storage consistent with the addressable bitset.\n\nExploitation note: local privilege escalation is possible on a 32-bit x86\nkernel using the under-allocation bug from a binary with CAP_BPF."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only via local bpf(2) syscalls: BPF_MAP_CREATE of BPF_MAP_TYPE_BLOOM_FILTER, then BPF_MAP_UPDATE_ELEM/LOOKUP_ELEM which call bloom_map_push_elem/peek_elem. Per kernel CNA guidance BPF is Local, not network-reachable.\nAC:L - On a 32-bit kernel the attacker deterministically forces the U32_MAX bitmap fallback with a large max_entries so BITS_TO_BYTES wraps and under-allocates; BPF_F_ZERO_SEED and chosen values then drive set_bit/test_bit to selected out-of-bounds indexes with no race or uncontrolled layout.\nPR:L - Creating a bloom-filter map requires CAP_BPF in map_create_alloc (bpf_token_capable). Per kernel guidance this is Low because CAP_BPF is obtainable via user namespaces and BPF token delegation, not only init-namespace root.\nUI:N - The attacker creates the undersized bloom map and issues lookup/update syscalls from their own process; no victim action such as mounting a filesystem or opening a file is required.\nS:U - The out-of-bounds bit set/test corrupts kernel heap around the undersized bloom object on the same host. This is standard kernel memory corruption and privilege escalation, not a VM escape or IOMMU boundary bypass.\nC:H - With bitset_mask==U32_MAX and a near-empty allocation, bloom_map_peek_elem's test_bit is an out-of-bounds kernel bit-read oracle, and the matching OOB writes enable heap disclosure; kernel guidance rates such memory corruption as High confidentiality impact.\nI:H - bloom_map_push_elem's set_bit writes past (and on 32-bit x86, before) the allocated object across a huge range, a controllable OOB write. The fix commit documents local privilege escalation from CAP_BPF on 32-bit x86.\nA:H - The same unbounded set_bit/test_bit indexes unmapped pages around the undersized kmalloc object and reliably produces a kernel oops or panic, which is High availability impact per kernel guidance."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/bloom_filter.c"],"versions":[{"version":"9330986c03006ab1d33d243b7cfe598a7a3c1baa","lessThan":"a6183bc683f97f4317f7e84939ca7fff37c5688b","status":"affected","versionType":"git"},{"version":"9330986c03006ab1d33d243b7cfe598a7a3c1baa","lessThan":"80551bf8912c42d1e3d55eec6fa3c40f306c3de8","status":"affected","versionType":"git"},{"version":"9330986c03006ab1d33d243b7cfe598a7a3c1baa","lessThan":"3b7a13eccfcf97714ffc1ca6aa663d66d4a30e29","status":"affected","versionType":"git"},{"version":"9330986c03006ab1d33d243b7cfe598a7a3c1baa","lessThan":"272fcb4ba6fab678db0eb966dc81c4c804bef64a","status":"affected","versionType":"git"},{"version":"9330986c03006ab1d33d243b7cfe598a7a3c1baa","lessThan":"dff481e12b3f127739f6a4ea7cef2c25dc12e056","status":"affected","versionType":"git"},{"version":"9330986c03006ab1d33d243b7cfe598a7a3c1baa","lessThan":"11c1e836710dcba03e50454a4eedfdbaf8d3050e","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/bloom_filter.c"],"versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a6183bc683f97f4317f7e84939ca7fff37c5688b"},{"url":"https://git.kernel.org/stable/c/80551bf8912c42d1e3d55eec6fa3c40f306c3de8"},{"url":"https://git.kernel.org/stable/c/3b7a13eccfcf97714ffc1ca6aa663d66d4a30e29"},{"url":"https://git.kernel.org/stable/c/272fcb4ba6fab678db0eb966dc81c4c804bef64a"},{"url":"https://git.kernel.org/stable/c/dff481e12b3f127739f6a4ea7cef2c25dc12e056"},{"url":"https://git.kernel.org/stable/c/11c1e836710dcba03e50454a4eedfdbaf8d3050e"}],"title":"bpf: Harden bloom filter sizing and indexing on 32-bit kernels","x_generator":{"engine":"bippy-1.2.0"}}}}