KernelScan.io

HIGH Introduced in 6.11

bpf Verifier DeltaTracking Bypass

CVE-2026-53092

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.7HIGH

01

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix linked reg delta tracking when src_reg == dst_reg Consider the case of rX += rX where src_reg and dst_reg are pointers to the same bpf_reg_state in adjust_reg_min_max_vals(). The latter first modifies the dst_reg in-place, and later in the delta tracking, the subsequent is_reg_const(src_reg)/reg_const_value(src_reg) reads the post-{add,sub} value instead of the original source. This is problematic since it sets an incorrect delta, which sync_linked_regs() then propagates to linked registers, thus creating a verifier-vs-runtime mismatch. Fix it by just skipping this corner case.

02

Engine v0.3.0

Risk summary

A local user with access to BPF program loading can craft a BPF program using a self-addition instruction (rX += rX) to cause the BPF verifier to track an incorrect register delta, creating a mismatch between what the verifier believes and what the CPU executes at runtime. This verifier-vs-runtime mismatch can be exploited to bypass BPF safety checks, potentially enabling memory corruption, information disclosure, or privilege escalation. Systems allowing unprivileged BPF program loading are most at risk.

Affectedkernel/bpf/verifier.c (BPF verifier)

Vulnerability analysis

The vulnerability is an incorrect calculation in the BPF verifier's linked register delta tracking logic introduced by commit 98d7ca374ba4. In adjust_reg_min_max_vals(), when processing an ADD or SUB instruction where src_reg and dst_reg point to the same bpf_reg_state (i.e., rX += rX), the function first modifies dst_reg in-place to reflect the arithmetic result, then attempts to read the source register's constant value via is_reg_const(src_reg)/reg_const_value(src_reg). Because src_reg and dst_reg are the same pointer, the source value read is the post-operation value rather than the original pre-operation value. This causes sync_linked_regs() to propagate an incorrect delta to all registers linked to dst_reg, creating a verifier-vs-runtime mismatch. An attacker can exploit this mismatch to make the verifier believe a register holds a value within safe bounds while at runtime it holds an out-of-bounds value, bypassing memory safety checks. The fix adds a guard to skip the delta tracking when src_reg == dst_reg (BPF_X encoding with identical src and dst register indices), preventing the incorrect delta from being computed and propagated.

03

BranchIntroducedFixed inPatch commit
6.126.116.12.1051509c1ae9185
7.06.117.0.10cc86a8b0a1c5
6.186.116.18.33d88e8e4a3b52
mainline6.117.1d7f14173c0d5