{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89581","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.728Z","datePublished":"2026-09-11T19:44:47.581Z","dateUpdated":"2026-09-13T06:31:15.157Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:31:15.157Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, x86: Fix per-CPU address resolution into an extended register\n\nThe destination of the per-CPU address MOV is encoded in ModRM.reg,\nwhich is extended by REX.R, but the REX prefix is built with\nadd_1mod(), which sets REX.B. REX.B extends ModRM.rm and SIB.base, and\nthis instruction addresses memory as disp32 with no base, so the bit\nhas no effect at all and the high register bit is simply lost.\n\nEvery is_ereg() destination therefore resolves to the wrong register,\npicking whichever one shares the low three bits:\n\n  R5 -> RAX    R7 -> RBP    R8 -> RSI    R9 -> RDI\n\nWith BPF_REG_5, whose reg2hex is 0, the emitted\n\n  65 49 03 04 25 <off>\tadd %gs:<off>,%rax\n\nadds the per-CPU offset to RAX rather than R8. The destination keeps\nthe unadjusted address and RAX is clobbered, so the program goes on to\ndereference a pointer that was never made per-CPU:\n\n  BUG: unable to handle page fault for address: 0000607e386a8894\n  RIP: bpf_prog_707837aafd2aa9ae_update_percpu_data+0x93/0xc9\n  Call Trace:\n   __bpf_prog_test_run_raw_tp+0x2dc/0x7d0\n   __flush_smp_call_function_queue+0x1e9/0xc80\n  Kernel panic - not syncing: Fatal exception in interrupt\n\nR5 is the mildest of the four, aliasing a scratch register and faulting\nat the store. R7 aliases RBP and would corrupt the frame pointer, R8\nand R9 alias the argument registers.\n\nUse add_2mod() so the register goes through REX.R, matching how\nadd_2reg() places it in ModRM.reg and how emit_priv_frame_ptr()\nhardcodes 0x4c for the same instruction with R9. Encodings for the\nnon-extended registers are unchanged.\n\nProblem showed up when trying to resurrect BPF_GCC CI (selftests built\nwith BPF_GCC).\n\nThis has gone unnoticed because clang reloads the address into R1\nbefore each per-CPU access, so the destination is never an extended\nregister. GCC keeps several per-CPU addresses live at once, and\ntest_progs-bpf_gcc panics the kernel in global_percpu_data/init, where\nthe address of a .percpu variable ends up in R5."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The x86 BPF JIT mis-encodes per-CPU address resolution in do_jit() in arch/x86/net/bpf_jit_comp.c. It is reached only when a local process loads a BPF program that uses .percpu globals or PERCPU_ARRAY direct-value ld_imm64 via bpf(2); kernel CNA guidance classifies BPF as Local.\nAC:L - The attacker chooses the ld_imm64 destination in their own bytecode; bpf_do_misc_fixups() always appends BPF_MOV64_PERCPU_REG on that same register, so targeting an extended register (BPF_REG_5/7/8/9) and hitting the wrong REX prefix is fully attacker-controlled, with no race or layout outside their influence.\nPR:L - Triggering the JIT path requires bpf(BPF_PROG_LOAD) with a PERCPU_ARRAY/.percpu map value (CAP_BPF, plus CAP_PERFMON for tracing types). PERCPU_ARRAY is an unprivileged map type, and CAP_BPF is delegable via BPF tokens/user namespaces, which kernel CNA guidance rates as Low rather than init-namespace root.\nUI:N - The attacker loads and runs their own crafted BPF program through bpf(2) (and optionally BPF_PROG_TEST_RUN); no separate victim action such as mounting a filesystem or opening a file is required.\nS:U - Wrong-register clobber and mis-resolved per-CPU pointer accesses corrupt memory inside the host kernel. This is standard in-kernel memory corruption/privilege escalation, not a VM escape, IOMMU bypass, or other cross-authority boundary.\nC:H - Missing REX.R leaves the destination holding an unadjusted __percpu offset that the verifier still types as a map-value pointer, so later loads read kernel memory at the wrong address; BPF_REG_7 also aliases RBP, sending stack-relative reads elsewhere and yielding a kernel disclosure primitive.\nI:H - The same mis-resolved pointer is used for verifier-approved map-value stores, and BPF_REG_7 clobbers RBP so subsequent JIT stack spills write to the wrong kernel address; that is attacker-controlled memory corruption exploitable for arbitrary write or control-flow hijack.\nA:H - The mis-encoded add leaves a non-per-CPU pointer that is then dereferenced, causing a kernel page-fault oops/panic (including in interrupt context via bpf_prog_test_run_raw_tp). Kernel CNA guidance rates any such crash as Availability High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/x86/net/bpf_jit_comp.c"],"versions":[{"version":"7bdbf7446305cb65c510c16d57cde82bc76b234a","lessThan":"638bc3aada8ecdece184d5c15b100d489c9cccd7","status":"affected","versionType":"git"},{"version":"7bdbf7446305cb65c510c16d57cde82bc76b234a","lessThan":"6886642414f59f928728802dc2c972a9859e6310","status":"affected","versionType":"git"},{"version":"7bdbf7446305cb65c510c16d57cde82bc76b234a","lessThan":"6a19b18d458881bf3269a357cc6dc6db5eef4369","status":"affected","versionType":"git"},{"version":"7bdbf7446305cb65c510c16d57cde82bc76b234a","lessThan":"5bbbce02e500d47d8e259a45be5a7be9741d0533","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/x86/net/bpf_jit_comp.c"],"versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/638bc3aada8ecdece184d5c15b100d489c9cccd7"},{"url":"https://git.kernel.org/stable/c/6886642414f59f928728802dc2c972a9859e6310"},{"url":"https://git.kernel.org/stable/c/6a19b18d458881bf3269a357cc6dc6db5eef4369"},{"url":"https://git.kernel.org/stable/c/5bbbce02e500d47d8e259a45be5a7be9741d0533"}],"title":"bpf, x86: Fix per-CPU address resolution into an extended register","x_generator":{"engine":"bippy-1.2.0"}}}}