{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93135","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T16:02:15.087Z","datePublished":"2026-09-17T16:11:36.771Z","dateUpdated":"2026-09-17T16:11:36.771Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-17T16:11:36.771Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject programs with inlined helpers if JIT is not available\n\nWhen an architecture (such as LoongArch, ARM64, and RISC-V) implements\nbpf_jit_inlines_helper_call(), the verifier skips rewriting the helper\ncall offset (insn->imm) in bpf_do_misc_fixups(). This is because the\nhelper is expected to be inlined by the JIT compiler later. Therefore,\ninsn->imm remains as the raw helper enum ID.\n\nHowever, if JIT is disabled at runtime (net.core.bpf_jit_enable=0) or\nif JIT compilation fails dynamically (e.g., due to OOM), the program\nfalls back to the BPF interpreter.\n\nWhen the interpreter executes (__bpf_call_base + insn->imm) with the\nunpatched raw ID, it jumps into an invalid address space, triggering\nan instruction alignment fault or a kernel panic.\n\nAlthough these helpers have valid C implementations in the kernel, the\nomission of offset rewriting makes runtime interpreter fallback fatal.\n\nFix this by setting 'prog->jit_required = 1' when helper call rewriting\nis skipped for JIT inlining. This ensures that such programs are safely\nrejected if JIT is not available, preventing the runtime kernel panic."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/fixups.c"],"versions":[{"version":"2ddec2c80b4402c293c7e6e0881cecaaf77e8cec","lessThan":"21c6445366795fa3a89954e1d318e7c8afdef843","status":"affected","versionType":"git"},{"version":"2ddec2c80b4402c293c7e6e0881cecaaf77e8cec","lessThan":"f1c27922576edccb99d0257827d09bd05c0304a6","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/fixups.c"],"versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/21c6445366795fa3a89954e1d318e7c8afdef843"},{"url":"https://git.kernel.org/stable/c/f1c27922576edccb99d0257827d09bd05c0304a6"}],"title":"bpf: Reject programs with inlined helpers if JIT is not available","x_generator":{"engine":"bippy-1.2.0"}}}}