{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89799","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.767Z","datePublished":"2026-09-16T10:30:31.487Z","dateUpdated":"2026-09-21T13:15:04.283Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-21T13:15:04.283Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Disable preemption in bpf_get_stackid\n\nThe get_perf_callchain call needs disabled preemption plus we need\nit disabled as long as we access its returned trace entries buffer.\n\nNote the bpf_get_stackid_pe function is executed already with\npreemption disabled."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - bpf_get_stackid is a tracing BPF helper (kprobe, tracepoint, raw_tp, perf_event, tracing/fentry) reached only after a local bpf(2) PROG_LOAD and attach; kernel CNA guidance classifies BPF as Local, with no network or USB path into this helper.\nAC:L - The attacker controls both sides of the race: a preemptible raw_tp/tracing program with a small STACK_TRACE map, and a same-CPU get_perf_callchain with larger max_depth that reuses the per-CPU entry after put_callchain_entry(). On PREEMPT kernels (e.g. Android) raw_tp uses migrate_disable only, so pinning and retries make the window reliably hittable.\nPR:L - Loading the required tracing programs needs CAP_BPF and CAP_PERFMON at bpf_prog_load(), and STACK_TRACE maps need CAP_BPF. Per kernel CNA guidance these are Low because BPF tokens and user namespaces can delegate them to non-init-namespace users, not only real root.\nUI:N - The attacker loads their own BPF program, attaches it to a tracepoint they can fire, and invokes bpf_get_stackid through their own syscalls or pinned threads; no victim mount, file open, or other user action is required.\nS:U - The out-of-bounds write corrupts the stack-map bucket slab inside the same host kernel security authority, enabling local privilege escalation; it does not cross a VM, IOMMU, or other distinct trust boundary.\nC:H - After put_callchain_entry(), a reused per-CPU entry can inflate trace->nr so memcpy/jhash2 and the build-id loop copy kernel instruction pointers past the attacker-sized stack_map_bucket, which is kernel memory corruption that can be turned into an arbitrary read primitive.\nI:H - Without a remaining size cap on the reused trace->nr, memcpy into the preallocated stack_map_bucket (sized to a small map value_size) or the bpf_stack_build_id store loop is an attacker-sized kernel heap OOB write, up to PERF_MAX_STACK_DEPTH frames, that can smash adjacent slab and hijack control flow.\nA:H - The same unbounded heap write past a small stack-map bucket causes a kernel oops or panic even when not fully weaponized, matching CNA guidance that any kernel crash or memory-corrupting OOB write is Availability High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/stackmap.c"],"versions":[{"version":"d5a3b1f691865be576c2bffa708549b8cdccda19","lessThan":"18c71e4b65ee60b8611fc071bdd7159f10185117","status":"affected","versionType":"git"},{"version":"d5a3b1f691865be576c2bffa708549b8cdccda19","lessThan":"ccf481d73bce6e851cec364fe831c86fe66877cf","status":"affected","versionType":"git"},{"version":"d5a3b1f691865be576c2bffa708549b8cdccda19","lessThan":"c4efdc1d4cb3e9183e41a1b2a5e0901dbbb31cdf","status":"affected","versionType":"git"},{"version":"d5a3b1f691865be576c2bffa708549b8cdccda19","lessThan":"15f1bd8574662f1b7b26aaa2e23ebf4066f0117d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/stackmap.c"],"versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/18c71e4b65ee60b8611fc071bdd7159f10185117"},{"url":"https://git.kernel.org/stable/c/ccf481d73bce6e851cec364fe831c86fe66877cf"},{"url":"https://git.kernel.org/stable/c/c4efdc1d4cb3e9183e41a1b2a5e0901dbbb31cdf"},{"url":"https://git.kernel.org/stable/c/15f1bd8574662f1b7b26aaa2e23ebf4066f0117d"}],"title":"bpf: Disable preemption in bpf_get_stackid","x_generator":{"engine":"bippy-1.2.0"}}}}