CVE-2026-68285
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: Fix memory leak in bpf_jit_free()
When bpf_int_jit_compile() is called for subprograms, it returns early during the first pass (!prog->is_func || extra_pass is false), keeping ctx->offset alive for the subsequent extra pass.
If JIT compilation fails for a later subprogram, the BPF core aborts and calls bpf_jit_free() to clean up the first subprogram. However, bpf_jit_free() fails to free jit_data->ctx.offset, which causes a memory leak of the JIT context offsets array.
So fix this by adding the missing kvfree(jit_data->ctx.offset) in bpf_jit_free().
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 4ab17e762b34c847478f694932c4cd4b1ac2c343 < f1557e0a64736b63aed24e285108a7bc3b7de294 | affected |
| Linux | Linux | 4ab17e762b34c847478f694932c4cd4b1ac2c343 < 47e20d4b3da97ef3881d1e55e43545c22424f3fc | affected |
| Linux | Linux | 7.0 | affected |
| Linux | Linux | 0 < 7.0 | unaffected |
| Linux | Linux | 7.1.6 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc5 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/f1557e0a64736b63aed24e285108a7bc3b7de294
- https://git.kernel.org/stable/c/47e20d4b3da97ef3881d1e55e43545c22424f3fc
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.