{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93138","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T16:02:15.088Z","datePublished":"2026-09-17T16:11:38.795Z","dateUpdated":"2026-09-18T17:56:10.073Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:56:10.073Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux\n\nbpf_get_btf_vmlinux() lazily parses the vmlinux BTF under the\nbpf_verifier_lock, but publishes the result through a plain store\nand re-checks it through a plain lockless load. Nothing orders\nthe stores initializing the struct btf inside btf_parse_vmlinux()\nagainst the store publishing the pointer: On a weakly ordered\narch, a concurrent first-time caller taking the lockless fast\npath could in principle observe the pointer before the parsed\ncontents are visible. The mutex_unlock() does not help such a\nreader given it only synchronizes with a later acquisition of the\nsame lock. Thus, publish the pointer with smp_store_release()\nand read it on the fast path with smp_load_acquire().\n\nAcquire semantics are needed rather than a dependency-ordered\nREAD_ONCE(): btf_parse_vmlinux() also populates globals outside\nthe returned object (e.g. bpf_ctx_convert.t). An address\ndependency would only order accesses performed through the\npointer and not cover other globals."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The race is reached from local bpf(2) BPF_PROG_LOAD: bpf_prog_load() calls bpf_get_btf_vmlinux() on the attach_btf_id path, and bpf_check() always calls it before verification. No remote protocol message carries the data that publishes btf_vmlinux.\nAC:L - The attacker issues concurrent BPF_PROG_LOAD (or BPF_MAP_CREATE of BPF_MAP_TYPE_STRUCT_OPS into bpf_struct_ops_map_alloc) so one thread runs btf_parse_vmlinux() under bpf_verifier_lock while the other takes the lockless `if (!btf_vmlinux)` load; they control both sides of that publication window.\nPR:L - The lockless consumer is bpf_check() when bpf_token_capable(token, CAP_BPF) sets is_priv and skips mutex_lock(&bpf_verifier_lock). CAP_BPF is delegable with a BPF token into a non-init user namespace, so init-namespace root is not required.\nUI:N - The attacker issues the concurrent bpf(BPF_PROG_LOAD) or bpf(BPF_MAP_CREATE) syscalls themselves; no other user must mount a filesystem, open a file, or load a program.\nS:U - A torn struct btf and bpf_ctx_convert.t are consumed by the host verifier and BTF helpers in the same kernel; that is in-kernel privilege escalation or DoS, not a KVM/Xen guest-to-host escape or IOMMU bypass.\nC:H - A lockless reader can observe btf_vmlinux before btf->types, btf->strings and btf->hdr.str_len are visible. btf_type_by_id() then returns btf->types[id] and btf_str_by_offset() returns &btf->strings[offset] (check_ptr_to_map_access, btf_find_by_name_kind), an unbounded kernel read.\nI:H - Privileged bpf_check() trusts that torn vmlinux BTF for PTR_TO_BTF_ID sizes, and get_kern_ctx_btf_id() walks bpf_ctx_convert.t members; garbage type metadata can accept illegal kernel stores. btf_get/btf_put on a not-yet-visible refcnt can also call_rcu btf_free_rcu of the live object.\nA:H - get_kern_ctx_btf_id() does btf_type_member(bpf_ctx_convert.t) with no NULL check when that global is still unseen, and check_ptr_to_map_access() loads t->name_off after btf_type_by_id() returns NULL because nr_types is still 0, oopsing the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/verifier.c"],"versions":[{"version":"8580ac9404f6240668a026785d7d8856f0530409","lessThan":"f32a4a40bc635be25d6816da4bd91e9e58c31bf3","status":"affected","versionType":"git"},{"version":"8580ac9404f6240668a026785d7d8856f0530409","lessThan":"a7fe72d780122eb934536f1719abad445f6afdf7","status":"affected","versionType":"git"},{"version":"8580ac9404f6240668a026785d7d8856f0530409","lessThan":"e18a10b39c994f04e1ebd7f8fc042bb1ca8ad053","status":"affected","versionType":"git"},{"version":"8580ac9404f6240668a026785d7d8856f0530409","lessThan":"978524ecfc1c539282df5858de1eec20748c6f74","status":"affected","versionType":"git"},{"version":"8580ac9404f6240668a026785d7d8856f0530409","lessThan":"eaf302628a78806f66d8224d6ba03fb4d5025de4","status":"affected","versionType":"git"},{"version":"8580ac9404f6240668a026785d7d8856f0530409","lessThan":"2892f3f44bf865c8fb6b6c0960edec4cc91806ee","status":"affected","versionType":"git"},{"version":"8580ac9404f6240668a026785d7d8856f0530409","lessThan":"86d11c594d60b255b526fa5260f669463fb1a063","status":"affected","versionType":"git"},{"version":"8580ac9404f6240668a026785d7d8856f0530409","lessThan":"92863e678070f57c17c868e4bfa2441a5c61ad2b","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/verifier.c"],"versions":[{"version":"5.5","status":"affected"},{"version":"0","lessThan":"5.5","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f32a4a40bc635be25d6816da4bd91e9e58c31bf3"},{"url":"https://git.kernel.org/stable/c/a7fe72d780122eb934536f1719abad445f6afdf7"},{"url":"https://git.kernel.org/stable/c/e18a10b39c994f04e1ebd7f8fc042bb1ca8ad053"},{"url":"https://git.kernel.org/stable/c/978524ecfc1c539282df5858de1eec20748c6f74"},{"url":"https://git.kernel.org/stable/c/eaf302628a78806f66d8224d6ba03fb4d5025de4"},{"url":"https://git.kernel.org/stable/c/2892f3f44bf865c8fb6b6c0960edec4cc91806ee"},{"url":"https://git.kernel.org/stable/c/86d11c594d60b255b526fa5260f669463fb1a063"},{"url":"https://git.kernel.org/stable/c/92863e678070f57c17c868e4bfa2441a5c61ad2b"}],"title":"bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux","x_generator":{"engine":"bippy-1.2.0"}}}}