Bug 2457626 (CVE-2026-31413)
| Summary: | CVE-2026-31413 kernel: bpf: Fix unsound scalar forking in maybe_fork_scalars() for BPF_OR | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel's Berkeley Packet Filter (BPF) component. This vulnerability arises from an incorrect handling of certain operations within the BPF verifier, which is responsible for ensuring the safety of BPF programs. This discrepancy between the verifier's analysis and the program's actual execution can be exploited by a local attacker. Successful exploitation could lead to out-of-bounds memory access, potentially allowing for privilege escalation or information disclosure.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-04-12 07:01:17 UTC
|