CVE-2026-93125: bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max
Published Sep 17, 2026
·Updated
bpf: Reject rdonly/rdwrbufsize kfunc arguments that exceed u32 max
Affected Software
1 affected component
Linux Kernel
Event History
Sep 17, 2026
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
DescriptionSeverity
Data Sourced
via NVD·05:18 PM
DescriptionSeverity
Sep 19, 2026
Data Sourced
via Microsoft·08:03 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which BPF programs are relevant to this issue?
The issue is relevant to BPF programs that call kfuncs with arguments named rdonly_buf_size or rdwr_buf_size. The problematic case is a constant size value whose upper 32 bits are set, meaning it exceeds U32_MAX.
2
When does the unsafe condition occur?
It occurs during BPF verifier processing when the kfunc argument size is recorded, and the value is later copied into a u32 mem_size field. The oversized value is truncated rather than rejected, causing subsequent access checks to use an incorrect bound.
3
How can I check whether a program uses the affected pattern?
Review kfunc calls in BPF programs for rdonly_buf_size or rdwr_buf_size arguments and identify constant values greater than U32_MAX. Such values should be rejected at program load time after the fix.