{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93111","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T16:02:15.086Z","datePublished":"2026-09-17T16:11:20.464Z","dateUpdated":"2026-09-18T17:55:58.964Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:58.964Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Mark tracing_multi trampolines as ftrace managed\n\nSince tracing_multi link does not set ftrace_managed, it would fail to\nrelease the tracing_multi link when attaching tracing_multi link and\nthen attaching fentry link.\n\n[    3.714215] WARNING: kernel/bpf/trampoline.c:1727 at bpf_trampoline_multi_detach+0x20b/0x240, CPU#1: test_progs/97\n...\n[    3.733170]  bpf_tracing_multi_link_release+0x14/0x30\n[    3.733890]  bpf_link_free+0x58/0x130\n[    3.734414]  bpf_link_release+0x23/0x30\n\nFix it by setting 'ftrace_managed = true' in register_fentry_multi()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Reached only via local bpf(2): BPF_PROG_LOAD of BPF_TRACE_FENTRY_MULTI then BPF_LINK_CREATE → link_create() → bpf_tracing_multi_attach() → register_fentry_multi(), then a regular BPF_TRACE_FENTRY BPF_LINK_CREATE through bpf_tracing_prog_attach(). The trigger is that attach order, not a remote protocol message.\nAC:L - The attacker chooses the order: tracing_multi first so register_fentry_multi() never sets tr->func.ftrace_managed, then fentry so modify_fentry() takes bpf_arch_text_poke() instead of direct_ops_mod(), then close() of the tracing_multi fd into bpf_trampoline_multi_detach(). No race or uninfluenced victim state is required.\nPR:L - bpf_prog_load() for BPF_PROG_TYPE_TRACING (fentry.multi and fentry) requires bpf_token_capable(CAP_BPF) and, via is_perfmon_prog_type(), bpf_token_capable(CAP_PERFMON). Those caps are delegable with a BPF token into a non-init user namespace, so this is Low rather than init-namespace root.\nUI:N - The attacker loads both programs, creates the tracing_multi and fentry links, and closes the tracing_multi fd themselves (bpf_link_release → bpf_tracing_multi_link_release). No other user must mount, open, or otherwise act on attacker-supplied objects.\nS:U - The use-after-free is of a kernel bpf_tramp_image that remains an ftrace direct-call target. That is in-kernel privilege escalation, not a KVM/Xen guest-to-host or IOMMU boundary cross, so scope stays Unchanged.\nC:H - modify_fentry() text-pokes the fentry site to Image B and bpf_tramp_image_put()s Image A; bpf_trampoline_multi_detach() still bpf_tramp_image_put()s Image B in bpf_trampoline_multi_attach_free() after update_ftrace_direct_del/mod fails, so a later call of the hooked function executes freed trampoline memory.\nI:H - The hooked function’s live CALL/JMP still targets the trampoline image bpf_trampoline_multi_attach_free() freed after the failed ftrace update, so reclaiming that JIT page hijacks control flow at the ftrace site (arbitrary kernel write/execute).\nA:H - bpf_trampoline_multi_detach() hits WARN_ON_ONCE(update_ftrace_direct_del()) at trampoline.c:1727 when ftrace’s recorded direct target no longer matches the poked site, and the subsequent jump into the freed bpf_tramp_image oopses or panics."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/trampoline.c"],"versions":[{"version":"aef4dfa790b22d8052cfb78044eadbe03c876c39","lessThan":"280145253fd38fa975cc04963ddaf74c7f415011","status":"affected","versionType":"git"},{"version":"aef4dfa790b22d8052cfb78044eadbe03c876c39","lessThan":"30bdd6d1384d894931f113eb595636092d8e650c","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/trampoline.c"],"versions":[{"version":"7.2","status":"affected"},{"version":"0","lessThan":"7.2","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/280145253fd38fa975cc04963ddaf74c7f415011"},{"url":"https://git.kernel.org/stable/c/30bdd6d1384d894931f113eb595636092d8e650c"}],"title":"bpf: Mark tracing_multi trampolines as ftrace managed","x_generator":{"engine":"bippy-1.2.0"}}}}