CVE-2026-68295: LoongArch: BPF: Zero-extend signed ALU32 div/mod results
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: Zero-extend signed ALU32 div/mod results
ALU32 operations write a 32-bit result and leave the upper 32 bits of the BPF register zero. The LoongArch JIT sign-extends the result of signed ALU32 BPFDIV and BPFMOD (off=1), so a negative 32-bit quotient or remainder leaves bits 63:32 set in JITted code while the verifier and interpreter model those bits as zero.
Keep sign-extension on the operands, which signed divide needs, and zero-extend the ALU32 result after the divide or modulo instruction, matching the unsigned ALU32 div/mod paths and every other ALU32 operation in this JIT.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68295?
CVE-2026-68295 has a risk score of 44.
How do I fix CVE-2026-68295?
To fix CVE-2026-68295, update your Linux kernel to the latest version where the vulnerability has been addressed.
What systems are affected by CVE-2026-68295?
CVE-2026-68295 affects systems utilizing the LoongArch architecture with specific configurations of the Linux kernel.
What impact does CVE-2026-68295 have on system security?
CVE-2026-68295 could potentially allow an attacker to exploit improper handling of signed ALU32 division and modulus operations.
When was CVE-2026-68295 published?
CVE-2026-68295 was published on August 10, 2026.