{"api_version":"1","generated_at":"2026-10-04T11:44:00+00:00","cve":"CVE-2026-89905","urls":{"html":"https://cve.report/CVE-2026-89905","api":"https://cve.report/api/cve/CVE-2026-89905.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89905","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89905"},"summary":{"title":"LoongArch: BPF: Move arena register slot below TCC context","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: BPF: Move arena register slot below TCC context\n\nCurrently, the stack layout places the optional arena register slot\nabove the tail call counter context. When arena_vm_start is dynamically\nenabled, it shifts the relative offset of the tcc_ptr slot within the\nstack frame, causing hardcoded tracking macros to mismatch and leading\nto memory misalignment or corruption potentially.\n\nTo fix this, move the arena register save and restore sequences below\nthe tail call counter context slots in both build_prologue() and the\nepilogue.\n\nUpdate __build_epilogue() to insert a proper offset decrement to safely\nskip the unneeded tcc_ptr reading block while accurately aligning with\nthe relocated arena slot at the very bottom.\n\nWith this patch, the tcc_ptr slot is always positioned at a fixed\ndistance directly underneath the base callee-saved registers that is\nindependent of whether the arena features are on.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-16 11:16:59","updated_at":"2026-09-16 11:16:59"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/cd7e356b07a27e91394838cf3fb655862b519294","name":"https://git.kernel.org/stable/c/cd7e356b07a27e91394838cf3fb655862b519294","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/f0e4d069cb47cf4f8dc4f6bc104e0671155aa3b9","name":"https://git.kernel.org/stable/c/f0e4d069cb47cf4f8dc4f6bc104e0671155aa3b9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89905","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89905","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected ef54c517a9376b188da06b5e1ed556129c4280be f0e4d069cb47cf4f8dc4f6bc104e0671155aa3b9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected ef54c517a9376b188da06b5e1ed556129c4280be cd7e356b07a27e91394838cf3fb655862b519294 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.0","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.5 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["arch/loongarch/net/bpf_jit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"f0e4d069cb47cf4f8dc4f6bc104e0671155aa3b9","status":"affected","version":"ef54c517a9376b188da06b5e1ed556129c4280be","versionType":"git"},{"lessThan":"cd7e356b07a27e91394838cf3fb655862b519294","status":"affected","version":"ef54c517a9376b188da06b5e1ed556129c4280be","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["arch/loongarch/net/bpf_jit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"7.0"},{"lessThan":"7.0","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.5","versionStartIncluding":"7.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"7.0","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: BPF: Move arena register slot below TCC context\n\nCurrently, the stack layout places the optional arena register slot\nabove the tail call counter context. When arena_vm_start is dynamically\nenabled, it shifts the relative offset of the tcc_ptr slot within the\nstack frame, causing hardcoded tracking macros to mismatch and leading\nto memory misalignment or corruption potentially.\n\nTo fix this, move the arena register save and restore sequences below\nthe tail call counter context slots in both build_prologue() and the\nepilogue.\n\nUpdate __build_epilogue() to insert a proper offset decrement to safely\nskip the unneeded tcc_ptr reading block while accurately aligning with\nthe relocated arena slot at the very bottom.\n\nWith this patch, the tcc_ptr slot is always positioned at a fixed\ndistance directly underneath the base callee-saved registers that is\nindependent of whether the arena features are on."}],"providerMetadata":{"dateUpdated":"2026-09-16T10:32:04.470Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/f0e4d069cb47cf4f8dc4f6bc104e0671155aa3b9"},{"url":"https://git.kernel.org/stable/c/cd7e356b07a27e91394838cf3fb655862b519294"}],"title":"LoongArch: BPF: Move arena register slot below TCC context","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-89905","datePublished":"2026-09-16T10:32:04.470Z","dateReserved":"2026-09-11T19:38:34.774Z","dateUpdated":"2026-09-16T10:32:04.470Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 11:16:59","lastModifiedDate":"2026-09-16 11:16:59","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89905","Ordinal":"1","Title":"LoongArch: BPF: Move arena register slot below TCC context","CVE":"CVE-2026-89905","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89905","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: BPF: Move arena register slot below TCC context\n\nCurrently, the stack layout places the optional arena register slot\nabove the tail call counter context. When arena_vm_start is dynamically\nenabled, it shifts the relative offset of the tcc_ptr slot within the\nstack frame, causing hardcoded tracking macros to mismatch and leading\nto memory misalignment or corruption potentially.\n\nTo fix this, move the arena register save and restore sequences below\nthe tail call counter context slots in both build_prologue() and the\nepilogue.\n\nUpdate __build_epilogue() to insert a proper offset decrement to safely\nskip the unneeded tcc_ptr reading block while accurately aligning with\nthe relocated arena slot at the very bottom.\n\nWith this patch, the tcc_ptr slot is always positioned at a fixed\ndistance directly underneath the base callee-saved registers that is\nindependent of whether the arena features are on.","Type":"Description","Title":"LoongArch: BPF: Move arena register slot below TCC context"}]}}}