Incorrect Conversion between Numeric Types in Linux kernel - CVE-2026-93127
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause an out-of-bounds access.
The vulnerability exists due to improper scalar identifier handling in the BPF verifier when processing sign-extending narrowing fills from spilled scalar stack slots. A local user can load a BPF program that combines sign-extending and zero-extending fills of the same stack slot to cause an out-of-bounds access.