{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93147","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T16:02:15.088Z","datePublished":"2026-09-17T16:11:44.793Z","dateUpdated":"2026-09-18T17:56:12.784Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:56:12.784Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/bpf: Replace ly instruction with llgf\n\ncpu_nr is a 32 bit value and BPF_REG_0 is a 64 bit register, when ly loads\nthe cpu_nr into BPF_REG_0 it does not zero the upper bits, but llgf does."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The malformed input is eBPF bytecode containing BPF_JMP|BPF_CALL with imm=BPF_FUNC_get_smp_processor_id, loaded via bpf_prog_load() (bpf(2) BPF_PROG_LOAD). s390 bpf_jit_insn() then inlines that call as LY from get_lowcore()->cpu_nr; no remote protocol carries this bytecode.\nAC:L - The attacker sets BPF_REG_0 (s390 %r14) with BPF_LD_IMM64, then emits the helper call; bpf_jit_insn() always compiles it to LY (E358), which writes only bits 32-63 and leaves the attacker-chosen high half intact. bpf_opt_remove_dead_code() does not delete that store, and there is no race.\nPR:L - bpf_prog_load() allows BPF_PROG_TYPE_SOCKET_FILTER; sk_filter_func_proto() reaches bpf_base_func_proto(), which returns bpf_get_raw_smp_processor_id_proto for BPF_FUNC_get_smp_processor_id before its CAP_BPF gate, and BPF_MAP_TYPE_ARRAY is an unprivileged map. CAP_BPF is also granted by bpf_token_capable() in a delegated user namespace.\nUI:N - The attacker loads the crafted program with bpf(BPF_PROG_LOAD) and executes it themselves via BPF_PROG_TEST_RUN (sk_filter_prog_ops.test_run = bpf_prog_test_run_skb) or SO_ATTACH_BPF on their own socket; no other user must mount, open, or otherwise act.\nS:U - LY leaving stale high bits in BPF_REG_0 lets the JITed program read and write the host kernel through a verifier-approved PTR_TO_MAP_VALUE. That stays inside the same kernel authority; it is not a KVM guest-to-host or IOMMU bypass.\nC:H - do_refine_retval_range() sets R0’s 64-bit range to [0, nr_cpu_ids-1] after BPF_FUNC_get_smp_processor_id, so check_map_access() allows adding it to a map-value pointer. LY preserves attacker high bits, so the subsequent BPF_LDX reads kernel memory far outside the map.\nI:H - The same forged pointer is a BPF_STX destination: the store lands at map_value + ((old_r0 & 0xFFFFFFFF00000000) | cpu_nr). That is an attacker-controlled kernel write usable for corruption and control-flow hijack.\nA:H - Using that out-of-bounds map-value pointer (map_value plus the uncleared high 32 bits of %r14 after LY of cpu_nr) faults on unmapped addresses and oopses or panics the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/s390/net/bpf_jit_comp.c"],"versions":[{"version":"9012cf2491e3c5d28d098b0d6da804af82977032","lessThan":"88500a86ab79f01c568de6ed00f5b1c5c79f11d5","status":"affected","versionType":"git"},{"version":"9012cf2491e3c5d28d098b0d6da804af82977032","lessThan":"5f6cc299938b561cb01e343bab7042611fcee12a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/s390/net/bpf_jit_comp.c"],"versions":[{"version":"7.2","status":"affected"},{"version":"0","lessThan":"7.2","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/88500a86ab79f01c568de6ed00f5b1c5c79f11d5"},{"url":"https://git.kernel.org/stable/c/5f6cc299938b561cb01e343bab7042611fcee12a"}],"title":"s390/bpf: Replace ly instruction with llgf","x_generator":{"engine":"bippy-1.2.0"}}}}