KernelScan.io

HIGH Introduced in 5.9

bpf SockOps OOB Read

CVE-2026-53078

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.1HIGH

01

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops When a BPF sock_ops program accesses ctx fields with dst_reg == src_reg, the SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros fail to zero the destination register in the !fullsock / !locked_tcp_sock path. Both macros borrow a temporary register to check is_fullsock / is_locked_tcp_sock when dst_reg == src_reg, because dst_reg holds the ctx pointer. When the check is false (e.g., TCP_NEW_SYN_RECV state with a request_sock), dst_reg should be zeroed but is not, leaving the stale ctx pointer: - SOCK_OPS_GET_SK: dst_reg retains the ctx pointer, passes NULL checks as PTR_TO_SOCKET_OR_NULL, and can be used as a bogus socket pointer, leading to stack-out-of-bounds access in helpers like bpf_skc_to_tcp6_sock(). - SOCK_OPS_GET_FIELD: dst_reg retains the ctx pointer which the verifier believes is a SCALAR_VALUE, leaking a kernel pointer. Fix both macros by: - Changing JMP_A(1) to JMP_A(2) in the fullsock path to skip the added instruction. - Adding BPF_MOV64_IMM(si->dst_reg, 0) after the temp register restore in the !fullsock path, placed after the restore because dst_reg == src_reg means we need src_reg intact to read ctx->temp.

02

Engine v0.3.0

Risk summary

A local user with access to BPF sock_ops programs can trigger a stack-out-of-bounds read or leak a kernel pointer when dst_reg equals src_reg and the socket is not a full socket (e.g., TCP_NEW_SYN_RECV state). This can be exploited to read kernel memory or cause a kernel crash. The vulnerability requires the ability to load BPF programs, which typically requires CAP_BPF or equivalent privilege.

Affectednet/core/filter.c (BPF sock_ops ctx access)

Vulnerability analysis

The root cause is in the SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros in net/core/filter.c. When dst_reg == src_reg, these macros borrow a temporary register to check is_fullsock/is_locked_tcp_sock. In the !fullsock path (e.g., TCP_NEW_SYN_RECV with a request_sock), the code restores the temporary register but fails to zero dst_reg. As a result, dst_reg retains the stale ctx pointer: SOCK_OPS_GET_SK leaves a ctx pointer that passes NULL checks as PTR_TO_SOCKET_OR_NULL, enabling stack-out-of-bounds access in helpers like bpf_skc_to_tcp6_sock(); SOCK_OPS_GET_FIELD leaves a ctx pointer that the verifier treats as a SCALAR_VALUE, leaking a kernel pointer to userspace. The fix changes JMP_A(1) to JMP_A(2) in the fullsock path to skip the new instruction, and adds BPF_MOV64_IMM(si->dst_reg, 0) after the temp register restore in the !fullsock path to properly zero the destination register. The attack requires loading a BPF sock_ops program with dst_reg == src_reg accessing certain ctx fields, which requires CAP_BPF (or CAP_NET_ADMIN on older kernels).

03

BranchIntroducedFixed inPatch commit
5.85.8.45.94c1c5efd9d1d
5.45.4.615.50e6b30657bbc
5.105.95.10.27064eaf4ecda00
5.155.95.15.2212a2c98141e0a
6.15.96.1.18822400725de07
6.65.96.6.15718e3ffde1822
6.125.96.12.10110f86a2a5c91
6.185.96.18.42—
7.05.97.0.10—
mainline5.97.1—
5.75.7.185.8db1200ec2c3d