CVE-2026-92519
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
riscv, bpf: Fix memory leak in bpf_jit_free
When bpf_int_jit_compile() is called for subprograms, it returns early during the first pass (!prog->is_func || extra_pass is false), keeping ctx->offset alive for the subsequent extra pass.
If JIT compilation fails for a later subprogram, the BPF core aborts and calls bpf_jit_free() to clean up the first subprogram. However, bpf_jit_free() fails to free jit_data->ctx.offset, which causes a memory leak of the JIT context offsets array.
Fix this by adding the missing kfree(jit_data->ctx.offset) in bpf_jit_free().
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 48a8f78c50bd6f7f08fd40daa62252fd043f2f18 < b594c23f584ab032a5eae809eee81b809dd27330 | affected |
| Linux | Linux | 48a8f78c50bd6f7f08fd40daa62252fd043f2f18 < 5cadc66b534fe8140441916200a20c7efb06a388 | affected |
| Linux | Linux | 48a8f78c50bd6f7f08fd40daa62252fd043f2f18 < 2a3a29e90021806ea00527f6458cfd2edb58b42a | affected |
| Linux | Linux | 48a8f78c50bd6f7f08fd40daa62252fd043f2f18 < 369e4635d04801f394d5bd42556f21029e95ff93 | affected |
| Linux | Linux | 6.6 | affected |
| Linux | Linux | 0 < 6.6 | unaffected |
| Linux | Linux | 6.12.110 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.52 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.6 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/b594c23f584ab032a5eae809eee81b809dd27330
- https://git.kernel.org/stable/c/5cadc66b534fe8140441916200a20c7efb06a388
- https://git.kernel.org/stable/c/2a3a29e90021806ea00527f6458cfd2edb58b42a
- https://git.kernel.org/stable/c/369e4635d04801f394d5bd42556f21029e95ff93
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.