CVE-2026-23383: bpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing
In the Linux kernel, the following vulnerability has been resolved:
bpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing
struct bpfplt contains a u64 target field. Currently, the BPF JIT allocator requests an alignment of 4 bytes (sizeof(u32)) for the JIT buffer.
Because the base address of the JIT buffer can be 4-byte aligned (e.g., ending in 0x4 or 0xc), the relative padding logic in buildplt() fails to ensure that target lands on an 8-byte boundary.
This leads to two issues: 1. UBSAN reports misaligned-access warnings when dereferencing the structure. 2. More critically, target is updated concurrently via WRITEONCE() in bpfarchtextpoke() while the JIT'd code executes ldr. On arm64, 64-bit loads/stores are only guaranteed to be single-copy atomic if they are 64-bit aligned. A misaligned target risks a torn read, causing the JIT to jump to a corrupted address.
Fix this by increasing the allocation alignment requirement to 8 bytes (sizeof(u64)) in bpfjitbinarypackalloc(). This anchors the base of the JIT buffer to an 8-byte boundary, allowing the relative padding math in buildplt() to correctly align the target field.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Force the BPF JIT buffer base to be 8-byte aligned (increase allocator alignment requirement from 4 bytes to 8 bytes) to prevent atomic tearing of the 64-bit plt target field on arm64.
Linux kernel eBPF JIT (bpf_jit_binary_pack_alloc / JIT buffer allocation) JIT buffer allocation alignment requirement = 8 bytes (alignment of u64)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23383?
The severity of CVE-2026-23383 is considered moderate as it involves a potential performance issue due to atomic tearing.
How do I fix CVE-2026-23383?
To fix CVE-2026-23383, update to the latest version of the Linux kernel that includes the patch addressing JIT buffer alignment.
What systems are affected by CVE-2026-23383?
CVE-2026-23383 affects the Linux kernel on arm64 architecture.
Is CVE-2026-23383 exploitable remotely?
CVE-2026-23383 is not considered remotely exploitable as it requires an attacker to have access to the local environment.
What impact does CVE-2026-23383 have on system performance?
CVE-2026-23383 may lead to degraded system performance due to potential atomic tearing in specific scenarios.