HIGH Introduced in 6.7
loongarch bpf JIT Bypass
CVE-2026-68295
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.8HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Zero-extend signed ALU32 div/mod results ALU32 operations write a 32-bit result and leave the upper 32 bits of the BPF register zero. The LoongArch JIT sign-extends the result of signed ALU32 BPF_DIV and BPF_MOD (off=1), so a negative 32-bit quotient or remainder leaves bits 63:32 set in JITted code while the verifier and interpreter model those bits as zero. Keep sign-extension on the operands, which signed divide needs, and zero-extend the ALU32 result after the divide or modulo instruction, matching the unsigned ALU32 div/mod paths and every other ALU32 operation in this JIT.
02KernelScan AI Analysis
Risk summary
A discrepancy between the LoongArch BPF JIT and the BPF verifier/interpreter allows signed ALU32 div/mod results to leave upper 32 bits set in JITted code, contradicting the verifier's zero-extension model. An unprivileged local attacker who can load BPF programs can exploit this to corrupt register state and achieve arbitrary kernel read/write, leading to privilege escalation. This requires a LoongArch platform with BPF JIT enabled and the ability to load BPF programs.
Vulnerability analysis
The LoongArch BPF JIT sign-extends the result of signed ALU32 divide and modulo operations, leaving the upper 32 bits of a BPF register set when the verifier and interpreter model them as zero. This mismatch lets a BPF program observe register values the verifier never accounted for, enabling out-of-bounds memory access and potential arbitrary kernel read/write. The fix zero-extends the ALU32 result after each signed div/mod instruction, matching the verifier's expectations and all other ALU32 operations. The vulnerable path is reachable by any local user who can load a BPF program on a LoongArch system with the JIT enabled; on most distributions unprivileged BPF is disabled, so exploitation typically requires CAP_BPF or equivalent privilege.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 7.1 | 6.7 | 7.1.6 | 716cb29dbed4 |
| mainline | 6.7 | 7.2-rc5 | dacd348b8a99 |