SB20260815165 - Improper access control in Linux kernel bpf
Published: August 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-74305)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass intended cgroup storage compatibility checks.
The vulnerability exists due to improper access control in bpf prog-array compatibility checks when validating tail-call chains involving cgroup local storage. A local user can load a storage-less BPF program that performs tail calls to bridge between programs with incompatible storage cookies to bypass intended cgroup storage compatibility checks.
Exploitation requires the ability to load and use BPF programs that participate in tail-call chains.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/10627ddc0167aab5c1c390a10ef461e9937aba08
- https://git.kernel.org/stable/c/1c762d28698483ce7c372091f34d86e4d4828652
- https://git.kernel.org/stable/c/46fbafe3d2d569d828e8d24a7dbe1659f63685cf
- https://git.kernel.org/stable/c/87177497cca90bf4fcfb759eb898560eb5b46a10
- https://git.kernel.org/stable/c/9ca06849c4239aa2d580c54651f8588c51cb398b
- https://git.kernel.org/stable/c/cb22dc79528eb26a46d346c3118dbd6b14c70609
- https://git.kernel.org/stable/c/eb73056ce2a6f101ddd3bdba89af6b24ebffff85