CVE-2026-93112

Summary

In the Linux kernel, the following vulnerability has been resolved:

bpf: Require a BPF cpumask for bpf_cpumask_populate()

bpf_cpumask_populate() writes to its destination with bitmap_copy(), but the destination is typed as struct cpumask *. That allows the verifier to accept borrowed cpumask pointers returned by read-only kfuncs, such as scx_bpf_get_online_cpumask(), as a writable destination.

Make the destination a struct bpf_cpumask * so populate follows the same ownership rule as the other mutating cpumask kfuncs. Query kfuncs continue to accept const struct cpumask * inputs.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux950ad93df2fce70445e655ed2e74f5c1a8653ab2 < 0cfc9348a045da64955af2dd6902e66dfc7d6469affected
LinuxLinux950ad93df2fce70445e655ed2e74f5c1a8653ab2 < b7e2a5c6519adc73be55c3de2cb545e095a0fbc5affected
LinuxLinux950ad93df2fce70445e655ed2e74f5c1a8653ab2 < 8740156ad33be5071b588b594c55f279457f667caffected
LinuxLinux6.15affected
LinuxLinux0 < 6.15unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References