{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-92518","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-16T12:21:13.873Z","datePublished":"2026-09-17T16:10:26.136Z","dateUpdated":"2026-09-18T17:55:36.191Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:36.191Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nriscv, bpf: Fix kernel stack corruption in tailcall with CFI\n\nWhen CONFIG_CFI_CLANG is enabled, prog->bpf_func already skips the kcfi\ninstruction during setup. Including it again in the tailcall jump offset\ncauses it to jump over an extra 4 bytes, skipping the stack pointer\nadjustment, which will result in kernel stack corruption."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The attacker-controlled input is a BPF program that uses bpf_tail_call, loaded via bpf(BPF_PROG_LOAD) in __sys_bpf(). emit_bpf_tail_call() then calls __build_epilogue(true), which emits the miscomputed jalr; no remote protocol carries that bytecode.\nAC:L - On CONFIG_CFI, bpf_int_jit_compile() sets prog->bpf_func to ro_insns+cfi_get_offset() (skipping the kcfi word), while __build_epilogue() still adds RV_KCFI_NINSNS to the jalr immediate, so every tail call lands past the prologue addi-to-SP. The attacker loads the caller/callee and runs them; no race or uninfluenced layout is required.\nPR:L - bpf_prog_load() allows BPF_PROG_TYPE_SOCKET_FILTER without CAP_BPF when unprivileged BPF is enabled, BPF_MAP_TYPE_PROG_ARRAY is created without CAP_BPF, and bpf_base_func_proto() returns bpf_tail_call_proto before the CAP_PERFMON gate. Otherwise only CAP_BPF or a delegated BPF token is required, not init-namespace root.\nUI:N - The attacker loads both programs, updates the PROG_ARRAY, and runs the caller with bpf(BPF_PROG_TEST_RUN) (sk_filter_prog_ops.test_run = bpf_prog_test_run_skb) or setsockopt(SO_ATTACH_BPF) on a socket they own. No other user must mount, open, or click.\nS:U - The skipped stack allocation corrupts the host kernel stack of the thread running the JITed image (bpf_prog_test_run_skb or sk_filter_trim_cap). That is in-kernel memory corruption on the same authority, not a KVM/Xen guest-to-host or IOMMU boundary crossing.\nC:H - After the tailcall jalr skips emit_addi(SP, SP, -stack_adjust), bpf_jit_build_prologue() still does emit_addi(S5, SP, bpf_stack_adjust), so BPF_REG_FP addresses the kernel caller's frame. FP-relative LDX then reads saved return addresses and locals from that frame.\nI:H - The same missed SP subtract means prologue sd of RA/FP/S1–S6 and BPF STX through S5 write into the kernel frame above SP. The callee epilogue then addi SP, SP, stack_adjust and jalr RA on that smashed frame, enabling a stack pivot and control-flow hijack.\nA:H - Returning from the tail-call target with SP still at the pre-BPF kernel SP, then adding stack_adjust in __build_epilogue(), misaligns the caller of bpf_prog_run so the kernel oopses or panics; any such crash is Availability High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/riscv/net/bpf_jit_comp64.c"],"versions":[{"version":"30a59cc79754fd9ff3f41b7ee2eb21da85988548","lessThan":"34b1bb33a025787e05f966e74de18cd36276f801","status":"affected","versionType":"git"},{"version":"30a59cc79754fd9ff3f41b7ee2eb21da85988548","lessThan":"a6e11a81da3420fd37f1518d4f238c4d5784086e","status":"affected","versionType":"git"},{"version":"30a59cc79754fd9ff3f41b7ee2eb21da85988548","lessThan":"52fb1756ea1d2759dfef2d86245be00b05dac3a2","status":"affected","versionType":"git"},{"version":"fe5b68fdcec0f3d97a32f4c4acfef59cf90718f7","status":"affected","versionType":"git"},{"version":"6.11.6","lessThan":"6.12","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/riscv/net/bpf_jit_comp64.c"],"versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11.6"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/34b1bb33a025787e05f966e74de18cd36276f801"},{"url":"https://git.kernel.org/stable/c/a6e11a81da3420fd37f1518d4f238c4d5784086e"},{"url":"https://git.kernel.org/stable/c/52fb1756ea1d2759dfef2d86245be00b05dac3a2"}],"title":"riscv, bpf: Fix kernel stack corruption in tailcall with CFI","x_generator":{"engine":"bippy-1.2.0"}}}}