Improper access control in Linux kernel - CVE-2026-93144
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to bypass read-only restrictions on untrusted BTF pointers.
The vulnerability exists due to improper access control in check_ptr_to_btf_access() in the BPF verifier when validating write accesses through untrusted BTF pointers. A local user can load a BPF program that performs a write through an untrusted BTF pointer to bypass read-only restrictions on untrusted BTF pointers.