CVE-2026-72111
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reset register bounds before narrowing retval range in check_mem_access()
When the BPF verifier processes a context load of an LSM hook return value, it calls __mark_reg_s32_range() to narrow the register to the hook's valid range. However, __mark_reg_s32_range() intersects the new range with the register's existing bounds using max_t()/min_t() rather than replacing them.
If the destination register carries stale bounds from a prior instruction (e.g. BPF_MOV64_IMM), the intersection can produce a range narrower than reality. The verifier then believes it knows the register's exact value, while at runtime the actual hook return value is loaded, creating a verifier/runtime mismatch that can be used to bypass BPF memory safety checks.
The else branch already calls mark_reg_unknown() to reset register state before any narrowing. Apply the same reset in the is_retval path so stale bounds are cleared before __mark_reg_s32_range() intersects.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 5d99e198be279045e6ecefe220f5c52f8ce9bfd5 < bde92f65042ec14389782dd223f706bf6b59ce5d | affected |
| Linux | Linux | 5d99e198be279045e6ecefe220f5c52f8ce9bfd5 < 0993dc5fc619c0b25ab1310cb11d65e78351c0fe | affected |
| Linux | Linux | 5d99e198be279045e6ecefe220f5c52f8ce9bfd5 < 5a55f9aecc08990940e70f0c7048a80850c5a16a | affected |
| Linux | Linux | 5d99e198be279045e6ecefe220f5c52f8ce9bfd5 < 5e0b273e0a62cc04ec338c7b502797c66c2ed42a | affected |
| Linux | Linux | 1050727d83e70449991c29dd1cf29fe936a63da3 | affected |
| Linux | Linux | 27ca3e20fe80be85a92b10064dfeb56cb2564b1c | affected |
| Linux | Linux | 6.10.13 < 6.11 | affected |
| Linux | Linux | 6.11.2 < 6.12 | affected |
| Linux | Linux | 6.12 | affected |
| Linux | Linux | 0 < 6.12 | unaffected |
| Linux | Linux | 6.12.103 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.40 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.5 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/bde92f65042ec14389782dd223f706bf6b59ce5d
- https://git.kernel.org/stable/c/0993dc5fc619c0b25ab1310cb11d65e78351c0fe
- https://git.kernel.org/stable/c/5a55f9aecc08990940e70f0c7048a80850c5a16a
- https://git.kernel.org/stable/c/5e0b273e0a62cc04ec338c7b502797c66c2ed42a
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.