{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-92517","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-16T12:21:13.873Z","datePublished":"2026-09-17T16:10:25.482Z","dateUpdated":"2026-09-17T16:10:25.482Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-17T16:10:25.482Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, riscv: Fix extable handling for arena load_acquire\n\nemit_atomic_ld_st() returns 1 to have build_body() skip the zext after\na sub-word load_acquire. The caller does \"ret = ret ?:\nadd_exception_handler(...)\", which skips add_exception_handler() on any\nnon-zero ret, so the extable entry is missing and a faulting\nPROBE_ATOMIC load_acquire oopses.\n\nREG_DONT_CLEAR_MARKER leaves rd stale on fault, and the verifier still\nthinks the load overwrote it, so a program can leak it through a map.\n\nCheck ret >= 0 before calling add_exception_handler(), and pass rd for\nLOAD_ACQ so the fault zeroes rd like a PROBE_MEM load. Return ret\nunchanged for the zext skip."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/riscv/net/bpf_jit_comp64.c"],"versions":[{"version":"fb7cefabae8117c203155ef169a386bec43bbba9","lessThan":"26d9496c826586338d1b8c27edfec4a19a89f462","status":"affected","versionType":"git"},{"version":"fb7cefabae8117c203155ef169a386bec43bbba9","lessThan":"08fe2eaa609180c1baeb76c2629a9c82263b0427","status":"affected","versionType":"git"},{"version":"fb7cefabae8117c203155ef169a386bec43bbba9","lessThan":"5eb8921371c6fd117d4a328b6053dfda38707df8","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/riscv/net/bpf_jit_comp64.c"],"versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/26d9496c826586338d1b8c27edfec4a19a89f462"},{"url":"https://git.kernel.org/stable/c/08fe2eaa609180c1baeb76c2629a9c82263b0427"},{"url":"https://git.kernel.org/stable/c/5eb8921371c6fd117d4a328b6053dfda38707df8"}],"title":"bpf, riscv: Fix extable handling for arena load_acquire","x_generator":{"engine":"bippy-1.2.0"}}}}