Incorrect calculation in Linux kernel - CVE-2026-89581
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to incorrect register encoding in the x86 BPF JIT compiler when resolving per-CPU addresses into extended registers. A local user can execute a BPF program that uses an extended register as a per-CPU address destination to cause a denial of service.