HIGH Introduced in 7.1
bpf PointerSpill Bypass
CVE-2026-72426
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI8.5HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve pointer spill metadata during half-slot cleanup __clean_func_state() cleans dead stack slots in 4-byte halves. When the high half of a STACK_SPILL slot is dead and the low half remains live, cleanup converts the live low half to STACK_MISC or STACK_ZERO and clears the saved spilled_ptr metadata. That conversion is safe only for scalar spills. For a pointer spill, this metadata clear lets a later 32-bit fill from the still-live half avoid the normal non-scalar register-fill check and be treated as an ordinary scalar stack read. Leave non-scalar spill slots intact in this half-live shape. This is conservative for pruning and preserves the existing check_stack_read_fixed_off() rejection path for partial fills from pointer spills.
02KernelScan AI Analysis
Risk summary
A flaw in the BPF verifier's stack-slot cleanup logic allows a spilled pointer to lose its type metadata when only half of its stack slot is dead. This lets a crafted BPF program read the pointer back as a scalar, bypassing verifier restrictions and enabling arbitrary kernel memory read/write. Any system allowing unprivileged BPF program loading or user namespaces is at risk of local privilege escalation and container escape.
Vulnerability analysis
The BPF verifier can lose track of pointer types during stack cleanup. When part of a pointer's stack slot is no longer needed but the rest remains in use, the cleanup routine converts the surviving portion to a generic value and forgets that it originally held a pointer. This allows a later read from that slot to be treated as an ordinary number instead of a pointer, bypassing the verifier's safety checks. A crafted BPF program can exploit this to obtain raw kernel pointer values and potentially access arbitrary kernel memory. The fix preserves pointer type information in this scenario, ensuring that partial reads from pointer spills continue to be blocked. The bug is reachable locally through the BPF program loading interface, which requires CAP_BPF — a capability available to unprivileged processes inside a user namespace on typical configurations.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 7.1 | 7.1 | 7.1.5 | 0f9278b22cda |
| mainline | 7.1 | 7.2-rc1 | 3a354149bcea |