{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93127","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T16:02:15.087Z","datePublished":"2026-09-17T16:11:31.253Z","dateUpdated":"2026-09-18T17:56:07.215Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:56:07.215Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Drop scalar id on sign-extending narrowing stack fills\n\nWhen a spilled scalar is filled back with a sign-extending narrowing load\n(BPF_MEMSX), check_stack_read_fixed_off() copies the spilled register\nincluding its scalar id, but coerce_reg_to_size_sx() then sign-extends the\nfilled register's value. If the same slot is also filled with a plain\nzero-extending load (BPF_MEM), both destination registers share the id yet\nhold different values. A later 'if <zext-reg> == const' then refines the\nsign-extended register through sync_linked_regs() to a value it does not\nhave at runtime (e.g. the verifier believes 0x80000000 while the register\nis 0xffffffff80000000), which can be turned into an out-of-bounds access.\n\nDrop the shared scalar id at the sign-extension site in check_mem_access()\nwhen sign extension actually changes the value, mirroring the BPF_MOVSX\nhandling in check_alu_op() (no_sext = reg_umax < 2^(size*8-1))."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The attacker-controlled input is BPF bytecode supplied via bpf(BPF_PROG_LOAD) in SYSCALL_DEFINE5(bpf) → bpf_prog_load() → bpf_check() → do_check_insn(); the bug fires on local BPF_LDX BPF_MEMSX/BPF_MEM stack fills in check_mem_access(), not on a remote protocol message.\nAC:L - The attacker writes the instruction sequence; ldsx_fill_scalar_id_not_shared deterministically spills a u32 with bit 31 set, fills it with *(s32*) into r4 and *(u32*) into r5, then uses if r5 == 0x80000000 so sync_linked_regs() poisons r4, with no race or external state.\nPR:L - check_stack_write_fixed_off()/check_stack_read_fixed_off() only preserve spilled scalar ids when env->bpf_capable, set from bpf_token_capable(CAP_BPF) in bpf_check(); unprivileged socket-filter loads therefore miss this path. CAP_BPF is delegable into a user namespace via bpf_token_create(), so this is Low, not init-namespace root.\nUI:N - The attacker loads the crafted program with bpf(BPF_PROG_LOAD), creates the hash map, and triggers bpf_map_lookup_elem plus the MEMSX/MEM fills themselves; no other user must mount media, open a file, or otherwise act.\nS:U - The confused r4 offset is applied to a PTR_TO_MAP_VALUE from bpf_map_lookup_elem() and corrupts host kernel heap in the same security authority; this is a verifier-bypass local privilege escalation, not a KVM/IOMMU guest-to-host crossing.\nC:H - After sync_linked_regs() copies known 0x80000000 onto the sign-extended r4 (runtime 0xffffffff80000000), r4 >>= 63 is believed 0 but is 1, so r0 += r4; *(u8*)(r0+7) on the 8-byte map value is an accepted out-of-bounds kernel read; repeating r0 += r4 yields an arbitrary-length read primitive.\nI:H - The same false r4==0 bound lets the verifier accept a store through that map-value pointer (replace the *(u8*)(r0+7) load with a store); repeating r0 += r4 before the store is an arbitrary kernel heap write usable for control-flow hijacking.\nA:H - The accepted program performs an out-of-bounds access on the bpf_map_lookup_elem() result (the selftest is rejected after the fix with \"R0 max value is outside of the allowed memory range\"); that heap OOB can oops or panic the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/verifier.c"],"versions":[{"version":"3cd5c890652ba1f0682adc291b5446245259b692","lessThan":"f3614622dc41f3dd99bb4f691da253814e4e6cae","status":"affected","versionType":"git"},{"version":"3cd5c890652ba1f0682adc291b5446245259b692","lessThan":"2cb5f4ca695ebe552647e5ba4aad6934d6a43bae","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/verifier.c"],"versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f3614622dc41f3dd99bb4f691da253814e4e6cae"},{"url":"https://git.kernel.org/stable/c/2cb5f4ca695ebe552647e5ba4aad6934d6a43bae"}],"title":"bpf: Drop scalar id on sign-extending narrowing stack fills","x_generator":{"engine":"bippy-1.2.0"}}}}