HIGH Introduced in 6.11
bpf Verifier DeltaTracking Bypass
CVE-2026-53092
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.7HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix linked reg delta tracking when src_reg == dst_reg Consider the case of rX += rX where src_reg and dst_reg are pointers to the same bpf_reg_state in adjust_reg_min_max_vals(). The latter first modifies the dst_reg in-place, and later in the delta tracking, the subsequent is_reg_const(src_reg)/reg_const_value(src_reg) reads the post-{add,sub} value instead of the original source. This is problematic since it sets an incorrect delta, which sync_linked_regs() then propagates to linked registers, thus creating a verifier-vs-runtime mismatch. Fix it by just skipping this corner case.
02KernelScan AI Analysis
Risk summary
A local user with access to BPF program loading can craft a BPF program using a self-addition instruction (rX += rX) to cause the BPF verifier to track an incorrect register delta, creating a mismatch between what the verifier believes and what the CPU executes at runtime. This verifier-vs-runtime mismatch can be exploited to bypass BPF safety checks, potentially enabling memory corruption, information disclosure, or privilege escalation. Systems allowing unprivileged BPF program loading are most at risk.
Vulnerability analysis
The vulnerability is an incorrect calculation in the BPF verifier's linked register delta tracking logic introduced by commit 98d7ca374ba4. In adjust_reg_min_max_vals(), when processing an ADD or SUB instruction where src_reg and dst_reg point to the same bpf_reg_state (i.e., rX += rX), the function first modifies dst_reg in-place to reflect the arithmetic result, then attempts to read the source register's constant value via is_reg_const(src_reg)/reg_const_value(src_reg). Because src_reg and dst_reg are the same pointer, the source value read is the post-operation value rather than the original pre-operation value. This causes sync_linked_regs() to propagate an incorrect delta to all registers linked to dst_reg, creating a verifier-vs-runtime mismatch. An attacker can exploit this mismatch to make the verifier believe a register holds a value within safe bounds while at runtime it holds an out-of-bounds value, bypassing memory safety checks. The fix adds a guard to skip the delta tracking when src_reg == dst_reg (BPF_X encoding with identical src and dst register indices), preventing the incorrect delta from being computed and propagated.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 6.11 | 6.12.105 | 1509c1ae9185 |
| 7.0 | 6.11 | 7.0.10 | cc86a8b0a1c5 |
| 6.18 | 6.11 | 6.18.33 | d88e8e4a3b52 |
| mainline | 6.11 | 7.1 | d7f14173c0d5 |