{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93144","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T16:02:15.088Z","datePublished":"2026-09-17T16:11:42.757Z","dateUpdated":"2026-09-18T17:56:11.444Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:56:11.444Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject writes through untrusted BTF pointers\n\ncheck_ptr_to_btf_access() lets program-type btf_struct_access callbacks\nvalidate writes before the default BTF access path rejects non-read\naccesses. That bypasses the read-only policy for untrusted BTF pointers\ncreated by helpers such as bpf_rdonly_cast().\n\nReject non-read accesses through PTR_UNTRUSTED BTF pointers at the\ncommon entry point, before the callback branch to handle all cases."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The attacker-controlled input is BPF bytecode that calls bpf_rdonly_cast() then STX, submitted via bpf(BPF_PROG_LOAD) in SYSCALL_DEFINE5(bpf) → bpf_prog_load() → bpf_check() → do_check_main() → check_mem_access() → check_ptr_to_btf_access(); no remote protocol carries that untrusted pointer or the store.\nAC:L - A BPF_PROG_TYPE_STRUCT_OPS program attached to bpf_dummy_ops (check_struct_ops_btf_id() sets env->ops to bpf_dummy_ops_btf_struct_access) or a BPF_PROG_TYPE_SCHED_CLS program (tc_cls_act_btf_struct_access) does bpf_rdonly_cast() then a store; the WRITE path ran the callback before the old \"only read is supported\" check. No race.\nPR:L - check_ptr_to_btf_access() returns -EPERM unless env->allow_ptr_leaks (bpf_token_capable(CAP_PERFMON)); STRUCT_OPS also fails is_perfmon_prog_type() without CAP_PERFMON, and add_subprog_and_kfunc() needs env->bpf_capable to emit bpf_rdonly_cast. bpf_token_capable() uses ns_capable() on a delegated token userns, not init-namespace root.\nUI:N - The attacker loads that program with BPF_PROG_LOAD and runs it via BPF_PROG_TEST_RUN (bpf_struct_ops_test_run() → dummy_ops_call_op() for bpf_dummy_ops, or bpf_prog_test_run_skb() for SCHED_CLS). No other user must mount, open a file, or cooperate.\nS:U - bpf_convert_ctx_accesses() leaves PTR_TO_BTF_ID|PTR_UNTRUSTED stores as plain STX (only reads become BPF_PROBE_MEM), so the write corrupts host kernel memory in the same authority as the bpf() caller; this is not a KVM/Xen guest-to-host escape or IOMMU bypass.\nC:H - The accepted STX writes attacker bytes through a bpf_rdonly_cast() pointer (obj__ign skips type checks) at bpf_dummy_ops_state.val, nf_conn.mark, or tcp_sock.snd_cwnd. That type-confused kernel write is a memory-corruption primitive that can be turned into an arbitrary kernel read.\nI:H - bpf_dummy_ops_btf_struct_access() accepts any store within sizeof(struct bpf_dummy_ops_state), and _nf_conntrack_btf_struct_access() accepts nf_conn.mark, on a PTR_UNTRUSTED base from bpf_rdonly_cast(); the JIT emits a plain store to that address, an arbitrary kernel write usable for control-flow hijacking.\nA:H - The same unprobed STX to bpf_rdonly_cast(0, btf_id) or to an out-of-bounds map/stack address page-faults in kernel context during bpf_struct_ops_test_run()/bpf_prog_test_run_skb() and oopses/panics, and the attacker can repeat BPF_PROG_TEST_RUN at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/verifier.c"],"versions":[{"version":"282de143ead96a5d53331e946f31c977b4610a74","lessThan":"19d5566b84ca1af0256d0d0003e1a081580c3ba3","status":"affected","versionType":"git"},{"version":"282de143ead96a5d53331e946f31c977b4610a74","lessThan":"ac65c710cc643cbc52b899627577357867249530","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/verifier.c"],"versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/19d5566b84ca1af0256d0d0003e1a081580c3ba3"},{"url":"https://git.kernel.org/stable/c/ac65c710cc643cbc52b899627577357867249530"}],"title":"bpf: Reject writes through untrusted BTF pointers","x_generator":{"engine":"bippy-1.2.0"}}}}