Out-of-bounds read in Linux kernel - CVE-2026-45839
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in bpf_core_parse_spec() when processing a crafted BPF program containing negative CO-RE accessor indices. A local privileged user can load a specially crafted BPF program to cause a denial of service.
The issue is reachable during BPF_PROG_LOAD on systems with CONFIG_DEBUG_INFO_BTF enabled.
How to mitigate CVE-2026-45839
Sources
- https://git.kernel.org/stable/c/1c22483a2c4bbf747787f328392ca3e68619c4dc
- https://git.kernel.org/stable/c/36a9012f76ba8d9189ae56a1f8bb7c87c07a1f3a
- https://git.kernel.org/stable/c/3ff85ae79e1a74baeb916b78a63d821f6d19a994
- https://git.kernel.org/stable/c/76f2ebaf79a9ae6d0737b87f045fe769e425d78f
- https://git.kernel.org/stable/c/99dbab7b5a12d8f58d5b0aa2f7a1fe656a70f4b2