Improper access control in Linux kernel - CVE-2026-80675
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to bypass metadata integrity validation.
The vulnerability exists due to improper access control in the signed loader metadata map verification logic when validating map metadata hashes for frozen maps. A remote user can load another BPF program with access to the same metadata map to mutate its contents after hash calculation to bypass metadata integrity validation.
Exploitation requires access to a non-exclusive metadata map used by the signed loader.