CVE-2026-72427: bpf: Fix effective prog array index with BPF_F_PREORDER
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix effective prog array index with BPFFPREORDER
replaceeffectiveprog() and purgeeffectiveprogs() located the slot in the effective array by walking the program hlist and counting entries linearly. That count does not match the array layout: computeeffective progs() places BPFFPREORDER programs at the front (ancestor cgroup first, attach order within a cgroup) and the rest after them (descendant cgroup first). So when a preorder program is present, the linear hlist position no longer equals the program's index in the effective array.
For replaceeffectiveprog() (bpflinkupdate()) this overwrote the wrong slot, corrupting the effective order. For purgeeffectiveprogs(), it could dummy out a slot belonging to a different program and leave the detached program in the array while bpfprogput() drops its reference, i.e. a use-after-free.
Fix both by replaying computeeffectiveprogs()'s placement (including the per-cgroup preorder reversal) in a shared effectiveprogpos() helper. Identify the entry by its struct bpfproglist pointer rather than by (prog, link) value, so the lookup resolves to exactly the attachment the syscall selected even when the same bpfprog is attached to several cgroups in the hierarchy.