{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89580","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.728Z","datePublished":"2026-09-11T19:44:46.846Z","dateUpdated":"2026-09-13T06:31:13.931Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:31:13.931Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Disable preemption in __bpf_get_stack\n\nget_perf_callchain() returns a per-CPU perf_callchain_entry buffer and\nreleases its recursion slot via put_callchain_entry() before returning,\nso nothing keeps the entry reserved while __bpf_get_stack() consumes\nit below.\n\nA preemptible BPF program (e.g. a non-sleepable raw tracepoint program\non a PREEMPT kernel, which runs under migrate_disable() but not\npreempt_disable()) can be scheduled out between obtaining the entry\nand the copy. Another task scheduled on the same CPU then reuses the\nsame per-CPU buffer and overwrites trace->nr with a larger value.\ncopy_len is then computed from the inflated trace->nr and can exceed\nthe caller's buffer, causing an out-of-bounds write in the memcpy()\nand in the build_id path.\n\nThe rcu_read_lock() taken here alone does not prevent this. It is\nonly taken on the may_fault path, and under CONFIG_PREEMPT_RCU it does\nnot disable preemption; it merely keeps perf's callchain buffer array\nalive (freed via call_rcu()) and does nothing to stop another task\nfrom reusing the entry.\n\nDisable preemption around obtaining the callchain entry and copying\nit into the caller's buffer, so the entry cannot be reused underneath\nus and trace->nr stays bounded by max_depth. Build ID resolution may\nfault and is therefore deferred until after preemption is re-enabled;\nby then the instruction pointers have already been copied into buf,\nso it operates only on that private copy. Note, preempt_disable() also\nsubsumes the buffer-lifetime guarantee the rcu_read_lock() provided,\nsince a preempt-disabled section is an RCU read-side critical section\nfor the callchain buffers' call_rcu() reclaim.\n\n\n[ changed Fixes: commit ]"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is in __bpf_get_stack(), reached only from bpf_get_stack/bpf_get_task_stack helpers in locally loaded tracing BPF (kprobe, tracepoint, raw_tp, perf_event, tracing) via bpf(2); kernel CNA guidance classifies BPF as Local, not a network path.\nAC:L - The attacker controls both sides of the race: a preemptible tracing program with a small bpf_get_stack buffer and a same-CPU helper/perf callchain with larger max_depth that reuses the per-CPU entry after put_callchain_entry(); pinning and retries make the window reliably hittable on PREEMPT kernels (e.g. Android).\nPR:L - Loading and attaching the required tracing programs needs CAP_BPF and CAP_PERFMON at bpf_prog_load(); per kernel CNA guidance these are Low because BPF tokens and user namespaces can delegate them to non-init-namespace users, not only real root.\nUI:N - The attacker loads their own BPF program, attaches it, and invokes the helper through their own syscalls or pinned threads; no victim mount, file open, or other user action is required.\nS:U - The out-of-bounds write corrupts kernel stack or slab inside the same host kernel security authority, enabling local privilege escalation; it does not cross a VM, IOMMU, or other distinct trust boundary.\nC:H - Inflated trace->nr drives memcpy/build-id copies of kernel instruction pointers past the caller buffer (BPF stack or map value), which is kernel memory corruption that can be turned into an arbitrary read primitive.\nI:H - copy_len is taken from the reused per-CPU trace->nr with no remaining size cap, so the memcpy or bpf_stack_build_id loop is an attacker-sized kernel OOB write (up to PERF_MAX_STACK_DEPTH frames) that can smash stack/heap and hijack control flow.\nA:H - The same unbounded kernel write past a small helper buffer causes a kernel oops or panic even when not fully weaponized, matching CNA guidance that any kernel crash or memory-corrupting OOB write is Availability High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/stackmap.c"],"versions":[{"version":"c195651e565ae7f41a68acb7d4aa7390ad215de1","lessThan":"8c5ba022f2085ea42d011497a6e92e527d123b9b","status":"affected","versionType":"git"},{"version":"c195651e565ae7f41a68acb7d4aa7390ad215de1","lessThan":"dbfecc8a6631c0d3626c14ba1f1a485a4498445a","status":"affected","versionType":"git"},{"version":"c195651e565ae7f41a68acb7d4aa7390ad215de1","lessThan":"9a23747909fcae707990c8466c381a0e7acfaa4e","status":"affected","versionType":"git"},{"version":"c195651e565ae7f41a68acb7d4aa7390ad215de1","lessThan":"b1a47b2708d4e95dbd23aee2ec83752190897b3f","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/stackmap.c"],"versions":[{"version":"4.18","status":"affected"},{"version":"0","lessThan":"4.18","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/8c5ba022f2085ea42d011497a6e92e527d123b9b"},{"url":"https://git.kernel.org/stable/c/dbfecc8a6631c0d3626c14ba1f1a485a4498445a"},{"url":"https://git.kernel.org/stable/c/9a23747909fcae707990c8466c381a0e7acfaa4e"},{"url":"https://git.kernel.org/stable/c/b1a47b2708d4e95dbd23aee2ec83752190897b3f"}],"title":"bpf: Disable preemption in __bpf_get_stack","x_generator":{"engine":"bippy-1.2.0"}}}}