SB20260815325 - Information disclosure in Linux kernel bpf



SB20260815325 - Information disclosure in Linux kernel bpf

Published: August 15, 2026

Security Bulletin ID SB20260815325
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Information disclosure (CVE-ID: CVE-2026-72402)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper access control in the BPF verifier log output in print_bpf_insn() when printing ldimm64 instructions with pointer-bearing pseudo sources. A local user can trigger verifier logging of crafted BPF instructions to disclose sensitive information.

The issue occurs when pointer leaks are not allowed but certain pseudo source types are still resolved to kernel pointer values before the verifier log prints the instruction.


Remediation

Install update from vendor's website.