SB20260828107 - Improper access control in Linux kernel lib bpf
Published: August 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-80675)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass metadata integrity validation.
The vulnerability exists due to improper access control in the signed loader metadata map verification logic when validating map metadata hashes for frozen maps. A remote user can load another BPF program with access to the same metadata map to mutate its contents after hash calculation to bypass metadata integrity validation.
Exploitation requires access to a non-exclusive metadata map used by the signed loader.
Remediation
Install update from vendor's website.