← Back to CVE List
CVE-2026-92518NVD
Vulnerability Summary
In the Linux kernel, the following vulnerability has been resolved:
riscv, bpf: Fix kernel stack corruption in tailcall with CFI
When CONFIG_CFI_CLANG is enabled, prog->bpf_func already skips the kcfi
instruction during setup. Including it again in the tailcall jump offset
causes it to jump over an extra 4 bytes, skipping the stack pointer
adjustment, which will result in kernel stack corruption.
riscv, bpf: Fix kernel stack corruption in tailcall with CFI
When CONFIG_CFI_CLANG is enabled, prog->bpf_func already skips the kcfi
instruction during setup. Including it again in the tailcall jump offset
causes it to jump over an extra 4 bytes, skipping the stack pointer
adjustment, which will result in kernel stack corruption.
CVSS v3.1 Base Metrics — Score 7.8 (HIGH)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Linux Linux >= 30a59cc79754fd9ff3f41b7ee2eb21da85988548 and < 34b1bb33a025787e05f966e74de18cd36276f801
- Linux Linux >= 30a59cc79754fd9ff3f41b7ee2eb21da85988548 and < a6e11a81da3420fd37f1518d4f238c4d5784086e
- Linux Linux >= 30a59cc79754fd9ff3f41b7ee2eb21da85988548 and < 52fb1756ea1d2759dfef2d86245be00b05dac3a2
- Linux Linux >= fe5b68fdcec0f3d97a32f4c4acfef59cf90718f7
- Linux Linux >= 6.11.6 and < 6.12
- Linux Linux >= 6.12
- Linux Linux 34b1bb33a025787e05f966e74de18cd36276f801
- Linux Linux a6e11a81da3420fd37f1518d4f238c4d5784086e
- Linux Linux 52fb1756ea1d2759dfef2d86245be00b05dac3a2
- Linux Linux 6.12