KernelScan.io

HIGH Introduced in 6.7

loongarch bpf JIT Bypass

CVE-2026-68295

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.8HIGH

01

In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Zero-extend signed ALU32 div/mod results ALU32 operations write a 32-bit result and leave the upper 32 bits of the BPF register zero. The LoongArch JIT sign-extends the result of signed ALU32 BPF_DIV and BPF_MOD (off=1), so a negative 32-bit quotient or remainder leaves bits 63:32 set in JITted code while the verifier and interpreter model those bits as zero. Keep sign-extension on the operands, which signed divide needs, and zero-extend the ALU32 result after the divide or modulo instruction, matching the unsigned ALU32 div/mod paths and every other ALU32 operation in this JIT.

02

Engine v0.6.0

Risk summary

A discrepancy between the LoongArch BPF JIT and the BPF verifier/interpreter allows signed ALU32 div/mod results to leave upper 32 bits set in JITted code, contradicting the verifier's zero-extension model. An unprivileged local attacker who can load BPF programs can exploit this to corrupt register state and achieve arbitrary kernel read/write, leading to privilege escalation. This requires a LoongArch platform with BPF JIT enabled and the ability to load BPF programs.

Affectedarch/loongarch/net/bpf_jit.c (LoongArch BPF JIT)

Vulnerability analysis

The LoongArch BPF JIT sign-extends the result of signed ALU32 divide and modulo operations, leaving the upper 32 bits of a BPF register set when the verifier and interpreter model them as zero. This mismatch lets a BPF program observe register values the verifier never accounted for, enabling out-of-bounds memory access and potential arbitrary kernel read/write. The fix zero-extends the ALU32 result after each signed div/mod instruction, matching the verifier's expectations and all other ALU32 operations. The vulnerable path is reachable by any local user who can load a BPF program on a LoongArch system with the JIT enabled; on most distributions unprivileged BPF is disabled, so exploitation typically requires CAP_BPF or equivalent privilege.

03

BranchIntroducedFixed inPatch commit
7.16.77.1.6716cb29dbed4
mainline6.77.2-rc5dacd348b8a99