KernelScan.io

HIGH Introduced in 7.1

bpf PointerSpill Bypass

CVE-2026-72426

CVSS 8.4 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI8.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve pointer spill metadata during half-slot cleanup __clean_func_state() cleans dead stack slots in 4-byte halves. When the high half of a STACK_SPILL slot is dead and the low half remains live, cleanup converts the live low half to STACK_MISC or STACK_ZERO and clears the saved spilled_ptr metadata. That conversion is safe only for scalar spills. For a pointer spill, this metadata clear lets a later 32-bit fill from the still-live half avoid the normal non-scalar register-fill check and be treated as an ordinary scalar stack read. Leave non-scalar spill slots intact in this half-live shape. This is conservative for pruning and preserves the existing check_stack_read_fixed_off() rejection path for partial fills from pointer spills.

02

Engine v0.6.0

Risk summary

A flaw in the BPF verifier's stack-slot cleanup logic allows a spilled pointer to lose its type metadata when only half of its stack slot is dead. This lets a crafted BPF program read the pointer back as a scalar, bypassing verifier restrictions and enabling arbitrary kernel memory read/write. Any system allowing unprivileged BPF program loading or user namespaces is at risk of local privilege escalation and container escape.

Affectedkernel/bpf/states.c (bpf verifier)

Vulnerability analysis

The BPF verifier can lose track of pointer types during stack cleanup. When part of a pointer's stack slot is no longer needed but the rest remains in use, the cleanup routine converts the surviving portion to a generic value and forgets that it originally held a pointer. This allows a later read from that slot to be treated as an ordinary number instead of a pointer, bypassing the verifier's safety checks. A crafted BPF program can exploit this to obtain raw kernel pointer values and potentially access arbitrary kernel memory. The fix preserves pointer type information in this scenario, ensuring that partial reads from pointer spills continue to be blocked. The bug is reachable locally through the BPF program loading interface, which requires CAP_BPF — a capability available to unprivileged processes inside a user namespace on typical configurations.

03

BranchIntroducedFixed inPatch commit
7.17.17.1.50f9278b22cda
mainline7.17.2-rc13a354149bcea