{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93045","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T15:57:05.658Z","datePublished":"2026-09-17T16:10:36.988Z","dateUpdated":"2026-09-18T17:55:45.700Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:45.700Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject arena frees below the arena base\n\nbpf_arena_free_pages() accepts scalar arena addresses. The runtime\nmasks the address to the low 32 bits and reconstructs a full user\naddress from the arena base before returning the range to the arena\nfree tree.\n\nWhen the scalar value is below the low 32 bits of the arena base,\nfull_uaddr falls below user_vm_start. The existing upper-end clipping\nthen turns this into an out-of-range free-tree offset. A later\nallocation can reuse that offset and return an address below the arena\nmapping.\n\nReject such frees before computing the clipped range."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The attacker-controlled input is the scalar ptr passed to bpf_arena_free_pages() from a locally loaded BPF program after bpf(BPF_MAP_CREATE) of BPF_MAP_TYPE_ARENA, mmap() of that map, bpf(BPF_PROG_LOAD), and bpf(BPF_PROG_TEST_RUN) (e.g. BPF_PROG_TYPE_SYSCALL). The below-base address is not carried in a network protocol message.\nAC:L - The attacker chooses the scalar whose low 32 bits are below (u32)arena->user_vm_start and the page_cnt passed to bpf_arena_free_pages(); compute_pgoff() then underflows and range_tree_set() records that offset deterministically. No race, victim state, or rare non-default config is required on JITs that implement bpf_jit_supports_arena() (x86_64/arm64).\nPR:L - map_create() requires bpf_token_capable(CAP_BPF) for BPF_MAP_TYPE_ARENA, and check_map_prog_compatibility() additionally requires CAP_PERFMON (env->allow_ptr_leaks) before a program may reference the arena. Those caps are delegable through BPF tokens into a user namespace rather than requiring init-namespace root.\nUI:N - The attacker creates their own arena map, mmap()s it so user_vm_start is set, loads their own program that calls bpf_arena_free_pages() with a below-base scalar, and runs it via BPF_PROG_TEST_RUN. No separate victim mount, open, or other interaction is required.\nS:U - arena_free_pages() corrupts the arena range_tree and kernel PTEs of the same host kernel that loaded the program. This is in-kernel memory unsafety, not a KVM/Xen guest-to-host escape or IOMMU/DMA boundary cross.\nC:H - With a below-base scalar and a large page_cnt, arena_free_pages() clips uaddr_end to user_vm_end so apply_to_existing_page_range() walks from kern_vm_start+uaddr32 across in-use arena PTEs and __free_page()s those pages while compute_pgoff() records a wrapped offset, leaving a page UAF that can disclose kernel memory.\nI:H - The same clipped free desynchronizes PTEs from the range_tree, and zap_pages() calls zap_vma_range() with full_uaddr below vma->vm_start, clearing mm PTEs outside the arena VMA. A later bpf_arena_alloc_pages() reuses the out-of-range offset via range_tree_find(), giving an exploitable page-reuse write primitive.\nA:H - Accessing a below-base pointer with a negative LDX/STX off faults below kern_vm_start, where bpf_arena_handle_page_fault() refuses recovery and oopses; zap_vma_range() also VM_WARN_ON_ONCE()s for a range outside the arena VMA, and the UAF of freed arena pages can panic the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/arena.c"],"versions":[{"version":"317460317a02a1af512697e6e964298dedd8a163","lessThan":"90453eaf8f14e7be0ab03983f2a93aeb6b990a58","status":"affected","versionType":"git"},{"version":"317460317a02a1af512697e6e964298dedd8a163","lessThan":"a968dffa5ab3c74d2ebb3a6233bf8b843f0bfc20","status":"affected","versionType":"git"},{"version":"317460317a02a1af512697e6e964298dedd8a163","lessThan":"8a08635656037aee9c12231ed384449c4ffb1a93","status":"affected","versionType":"git"},{"version":"317460317a02a1af512697e6e964298dedd8a163","lessThan":"b5a71cb2db6d84ac0042549dcec266b18429d41e","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/arena.c"],"versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/90453eaf8f14e7be0ab03983f2a93aeb6b990a58"},{"url":"https://git.kernel.org/stable/c/a968dffa5ab3c74d2ebb3a6233bf8b843f0bfc20"},{"url":"https://git.kernel.org/stable/c/8a08635656037aee9c12231ed384449c4ffb1a93"},{"url":"https://git.kernel.org/stable/c/b5a71cb2db6d84ac0042549dcec266b18429d41e"}],"title":"bpf: Reject arena frees below the arena base","x_generator":{"engine":"bippy-1.2.0"}}}}