Bug 2536785 (CVE-2026-93144) - CVE-2026-93144 kernel: bpf: Reject writes through untrusted BTF pointers
Summary: CVE-2026-93144 kernel: bpf: Reject writes through untrusted BTF pointers
Keywords:
Status: NEW
Alias: CVE-2026-93144
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-17 19:33 UTC by OSIDB Bzimport
Modified: 2026-09-30 16:26 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-17 19:33:12 UTC
In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject writes through untrusted BTF pointers

check_ptr_to_btf_access() lets program-type btf_struct_access callbacks
validate writes before the default BTF access path rejects non-read
accesses. That bypasses the read-only policy for untrusted BTF pointers
created by helpers such as bpf_rdonly_cast().

Reject non-read accesses through PTR_UNTRUSTED BTF pointers at the
common entry point, before the callback branch to handle all cases.


Note You need to log in before you can comment on or make changes to this bug.