Out-of-bounds read in Linux kernel - CVE-2026-53076
Published: June 25, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in pcpu_init_value in the BPF hashtab implementation when copying an element from a BPF_MAP_TYPE_CGROUP_STORAGE map to another per-cpu map with the same non-8-byte-aligned value_size. A local user can update the destination map with data from the crafted source map to disclose sensitive information.
The issue occurs when the source map value size is not rounded up to 8 bytes, causing a copy operation to read past the claimed source size.
Affected software
Ubuntu
linux (Ubuntu package)
linux-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-ibm (Ubuntu package)
linux-oracle-6.8 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-aws (Ubuntu package)
linux-raspi (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-gcp-fips (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-nvidia-bos (Ubuntu package)
How to mitigate CVE-2026-53076
linux (Ubuntu package) - addressed in versions 6.8.0-136.136, 6.8.0-1046.50, 6.8.0-1059.67, 6.8.0-1064.72, 6.8.0-1064.72~22.04.1, 6.8.1-1056.57, 6.8.1-1056.57~22.04.2, 7.0.0-28.28, 7.0.0-28.28.1, 7.0.0-1003.4, 7.0.0-1008.8
linux-fips (Ubuntu package) - addressed in versions 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-ibm (Ubuntu package) - addressed in versions 6.8.0-1030.31, 6.8.0-1033.34, 6.8.0-1061.62, 6.8.0-1061.62~22.04.1, 7.0.0-1008.8, 7.0.0-1010.10
linux-oracle-6.8 (Ubuntu package) - update to 6.8.0-1058.61~22.04.1
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1059.62, 6.8.0-1059.62.1, 6.8.0-1059.62~22.04.1, 7.0.0-1016.16, 7.0.0-1016.16~24.04.1
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1061.64+fips1, 6.8.0-1061.64~22.04.1
linux-aws (Ubuntu package) - addressed in versions 6.8.0-1061.64+1, 7.0.0-1009.9, 7.0.0-1015.15
linux-raspi (Ubuntu package) - addressed in versions 6.8.0-1061.65, 6.8.0-2050.52
linux-azure-fde (Ubuntu package) - update to 6.8.0-1062.69
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1063.71, 6.8.0-1063.71~22.04.1, 7.0.0-1009.9, 7.0.0-1010.10
linux-azure-fips (Ubuntu package) - update to 6.8.0-1063.71+fips2
linux-gcp-fips (Ubuntu package) - update to 6.8.0-1064.72+fips1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1009.9
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2016.16
External References
- https://git.kernel.org/stable/c/576afddfee8d1108ee299bf10f581593540d1a36
- https://git.kernel.org/stable/c/6086079e6d1c32ba4c4b422612b8aebb1129a96c
- https://git.kernel.org/stable/c/634a793d0e1c822412095d25a1338f8831ad894c
- https://git.kernel.org/stable/c/e0378419b0e20178b5d100b27c9cc7e51064202e
- https://git.kernel.org/stable/c/e19c5ed9f1922a6854073f8651a63fa7be26e9e9
Related Security Bulletins
- Out-of-bounds read in Linux kernel bpf
- Ubuntu update for linux-oem-7.0
- Ubuntu update for linux
- Ubuntu update for linux
- Ubuntu update for linux-gcp-fips
- Ubuntu update for linux-oracle-6.8
- Ubuntu update for linux-fips
- Ubuntu update for linux-ibm
- Ubuntu update for linux-nvidia
- Ubuntu update for linux-azure
- Ubuntu update for linux-azure-fde-6.8
- Ubuntu update for linux-azure-fips
- Ubuntu update for linux-azure-fde
- Ubuntu update for linux-azure
- Ubuntu update for linux-aws
- Ubuntu update for linux-hwe-6.8
- Ubuntu update for linux-aws-6.8
- Ubuntu update for linux-ibm
- Ubuntu update for linux-aws
- Ubuntu update for linux-raspi
- Ubuntu update for linux-nvidia-bos
- Ubuntu update for linux-nvidia