HIGH Introduced in 5.9
bpf SockOps OOB Read
CVE-2026-53078
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.1HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops When a BPF sock_ops program accesses ctx fields with dst_reg == src_reg, the SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros fail to zero the destination register in the !fullsock / !locked_tcp_sock path. Both macros borrow a temporary register to check is_fullsock / is_locked_tcp_sock when dst_reg == src_reg, because dst_reg holds the ctx pointer. When the check is false (e.g., TCP_NEW_SYN_RECV state with a request_sock), dst_reg should be zeroed but is not, leaving the stale ctx pointer: - SOCK_OPS_GET_SK: dst_reg retains the ctx pointer, passes NULL checks as PTR_TO_SOCKET_OR_NULL, and can be used as a bogus socket pointer, leading to stack-out-of-bounds access in helpers like bpf_skc_to_tcp6_sock(). - SOCK_OPS_GET_FIELD: dst_reg retains the ctx pointer which the verifier believes is a SCALAR_VALUE, leaking a kernel pointer. Fix both macros by: - Changing JMP_A(1) to JMP_A(2) in the fullsock path to skip the added instruction. - Adding BPF_MOV64_IMM(si->dst_reg, 0) after the temp register restore in the !fullsock path, placed after the restore because dst_reg == src_reg means we need src_reg intact to read ctx->temp.
02KernelScan AI Analysis
Risk summary
A local user with access to BPF sock_ops programs can trigger a stack-out-of-bounds read or leak a kernel pointer when dst_reg equals src_reg and the socket is not a full socket (e.g., TCP_NEW_SYN_RECV state). This can be exploited to read kernel memory or cause a kernel crash. The vulnerability requires the ability to load BPF programs, which typically requires CAP_BPF or equivalent privilege.
Vulnerability analysis
The root cause is in the SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros in net/core/filter.c. When dst_reg == src_reg, these macros borrow a temporary register to check is_fullsock/is_locked_tcp_sock. In the !fullsock path (e.g., TCP_NEW_SYN_RECV with a request_sock), the code restores the temporary register but fails to zero dst_reg. As a result, dst_reg retains the stale ctx pointer: SOCK_OPS_GET_SK leaves a ctx pointer that passes NULL checks as PTR_TO_SOCKET_OR_NULL, enabling stack-out-of-bounds access in helpers like bpf_skc_to_tcp6_sock(); SOCK_OPS_GET_FIELD leaves a ctx pointer that the verifier treats as a SCALAR_VALUE, leaking a kernel pointer to userspace. The fix changes JMP_A(1) to JMP_A(2) in the fullsock path to skip the new instruction, and adds BPF_MOV64_IMM(si->dst_reg, 0) after the temp register restore in the !fullsock path to properly zero the destination register. The attack requires loading a BPF sock_ops program with dst_reg == src_reg accessing certain ctx fields, which requires CAP_BPF (or CAP_NET_ADMIN on older kernels).
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.8 | 5.8.4 | 5.9 | 4c1c5efd9d1d |
| 5.4 | 5.4.61 | 5.5 | 0e6b30657bbc |
| 5.10 | 5.9 | 5.10.270 | 64eaf4ecda00 |
| 5.15 | 5.9 | 5.15.221 | 2a2c98141e0a |
| 6.1 | 5.9 | 6.1.188 | 22400725de07 |
| 6.6 | 5.9 | 6.6.157 | 18e3ffde1822 |
| 6.12 | 5.9 | 6.12.101 | 10f86a2a5c91 |
| 6.18 | 5.9 | 6.18.42 | — |
| 7.0 | 5.9 | 7.0.10 | — |
| mainline | 5.9 | 7.1 | — |
| 5.7 | 5.7.18 | 5.8 | db1200ec2c3d |