{"api_version":"1","generated_at":"2026-09-19T15:00:35+00:00","cve":"CVE-2026-93148","urls":{"html":"https://cve.report/CVE-2026-93148","api":"https://cve.report/api/cve/CVE-2026-93148.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-93148","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-93148"},"summary":{"title":"bpf: Reject MEM_ALLOC BTF accesses past object bounds","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject MEM_ALLOC BTF accesses past object bounds\n\nBTF struct walks relax the struct-size check for accesses through a\ntrailing flexible array. That is valid for ordinary BTF type walking, but\nPTR_TO_BTF_ID | MEM_ALLOC values point to objects allocated with the static\nBTF type size.\n\nWhen walking a MEM_ALLOC object, reject the access before applying the\nflexible-array relaxation if the access range extends past the struct size.\nApply the same policy to struct ID matching so kfunc and kptr type checks\ndo not walk past the allocated object bounds either.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:18:09","updated_at":"2026-09-18 18:18:22"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/9c9ee0324c774490ae953162aaaf4561d222bd93","name":"https://git.kernel.org/stable/c/9c9ee0324c774490ae953162aaaf4561d222bd93","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e626a50d07d43421cbf7bfb5a084b33a5e276b6e","name":"https://git.kernel.org/stable/c/e626a50d07d43421cbf7bfb5a084b33a5e276b6e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-93148","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93148","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 958cf2e273f0929c66169e0788031310e8118722 e626a50d07d43421cbf7bfb5a084b33a5e276b6e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 958cf2e273f0929c66169e0788031310e8118722 9c9ee0324c774490ae953162aaaf4561d222bd93 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.2","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.2 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"93148","cve":"CVE-2026-93148","epss":"0.001550000","percentile":"0.051270000","score_date":"2026-09-18","updated_at":"2026-09-19 00:06:16"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["include/linux/bpf.h","kernel/bpf/btf.c","kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"e626a50d07d43421cbf7bfb5a084b33a5e276b6e","status":"affected","version":"958cf2e273f0929c66169e0788031310e8118722","versionType":"git"},{"lessThan":"9c9ee0324c774490ae953162aaaf4561d222bd93","status":"affected","version":"958cf2e273f0929c66169e0788031310e8118722","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["include/linux/bpf.h","kernel/bpf/btf.c","kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.2"},{"lessThan":"6.2","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"6.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"6.2","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject MEM_ALLOC BTF accesses past object bounds\n\nBTF struct walks relax the struct-size check for accesses through a\ntrailing flexible array. That is valid for ordinary BTF type walking, but\nPTR_TO_BTF_ID | MEM_ALLOC values point to objects allocated with the static\nBTF type size.\n\nWhen walking a MEM_ALLOC object, reject the access before applying the\nflexible-array relaxation if the access range extends past the struct size.\nApply the same policy to struct ID matching so kfunc and kptr type checks\ndo not walk past the allocated object bounds either."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The attacker-controlled input is program BTF (a struct whose last member is a 0-element array) plus LDX/STX offsets in bytecode that bpf_prog_load() copies from bpf(2) BPF_PROG_LOAD (__sys_bpf). bpf_check() then check_mem_access()->check_ptr_to_btf_access()->btf_struct_access()->btf_struct_walk() on the bpf_obj_new PTR_TO_BTF_ID|MEM_ALLOC; no remote protocol carries that BTF or those offsets.\nAC:L - The attacker defines the local struct with a trailing nelems==0 array, calls bpf_obj_new (allocated at ret_t->size via bpf_mem_alloc(&bpf_global_ma)), then LDX/STX at off past t->size. Pre-fix btf_struct_walk() applied the flexible-array relaxation whenever off+size > t->size; no race or uninfluenced layout is required.\nPR:L - add_subprog_and_kfunc() returns -EPERM unless env->bpf_capable (bpf_token_capable(CAP_BPF)) because bpf_obj_new is a kfunc; check_ptr_to_btf_access() also needs bpf_allow_ptr_leaks() (CAP_PERFMON). BPF_PROG_TYPE_SYSCALL is not is_perfmon_prog_type(); bpf_token_capable() uses ns_capable() on a delegated token userns, not init-namespace root.\nUI:N - The attacker BPF_PROG_LOADs that program and runs it with BPF_PROG_TEST_RUN (bpf_prog_test_run_syscall) so bpf_obj_new() and the OOB LDX/STX execute in that same task. No other user must mount a filesystem, open a file, or otherwise cooperate.\nS:U - btf_struct_walk() approving the flexible-array access causes the JIT/interpreter to LDX/STX past the bpf_mem_alloc() object in bpf_global_ma in the same host kernel that loaded the program. That is in-kernel heap OOB and privilege escalation, not a KVM/Xen guest-to-host escape or IOMMU bypass.\nC:H - For a MEM_ALLOC object whose last BTF member is a 0-element int array, btf_struct_walk() returned WALK_SCALAR for any off past the FAM with no upper bound. bpf_convert_ctx_accesses() does not rewrite PTR_TO_BTF_ID|MEM_ALLOC to BPF_PROBE_MEM, so those LDXes are plain loads of adjacent bpf_mem_cache/kmalloc objects.\nI:H - check_ptr_to_btf_access() permits BPF_WRITE on type_is_ptr_alloc_obj() (PTR_TO_BTF_ID|MEM_ALLOC). The same FAM relaxation therefore approves STX past bpf_obj_new()'s ret_t->size into the bpf_global_ma size-class unit (padding and the next object), a controllable kernel heap write. btf_struct_ids_match walking past those bounds can also mis-type kptr/kfunc pointers.\nA:H - Unbounded LDX/STX past the bpf_obj_new allocation in bpf_global_ma can corrupt adjacent bpf_mem_cache units or load unmapped addresses, oopsing or panicking the kernel when the program runs under bpf_prog_test_run_syscall, and the attacker can repeat that run at will."}]}],"providerMetadata":{"dateUpdated":"2026-09-18T17:56:14.130Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/e626a50d07d43421cbf7bfb5a084b33a5e276b6e"},{"url":"https://git.kernel.org/stable/c/9c9ee0324c774490ae953162aaaf4561d222bd93"}],"title":"bpf: Reject MEM_ALLOC BTF accesses past object bounds","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-93148","datePublished":"2026-09-17T16:11:45.457Z","dateReserved":"2026-09-17T16:02:15.088Z","dateUpdated":"2026-09-18T17:56:14.130Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:18:09","lastModifiedDate":"2026-09-18 18:18:22","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"93148","Ordinal":"1","Title":"bpf: Reject MEM_ALLOC BTF accesses past object bounds","CVE":"CVE-2026-93148","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"93148","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject MEM_ALLOC BTF accesses past object bounds\n\nBTF struct walks relax the struct-size check for accesses through a\ntrailing flexible array. That is valid for ordinary BTF type walking, but\nPTR_TO_BTF_ID | MEM_ALLOC values point to objects allocated with the static\nBTF type size.\n\nWhen walking a MEM_ALLOC object, reject the access before applying the\nflexible-array relaxation if the access range extends past the struct size.\nApply the same policy to struct ID matching so kfunc and kptr type checks\ndo not walk past the allocated object bounds either.","Type":"Description","Title":"bpf: Reject MEM_ALLOC BTF accesses past object bounds"}]}}}