cbcvebase.
CVE-2026-23417
published 2026-04-02

CVE-2026-23417: In the Linux kernel, the following vulnerability has been resolved: bpf: Fix constant blinding for PROBE_MEM32 stores BPF_ST | BPF_PROBE_MEM32 immediate stores…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
1.9th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix constant blinding for PROBE_MEM32 stores BPF_ST | BPF_PROBE_MEM32 immediate stores are not handled by bpf_jit_blind_insn(), allowing user-controlled 32-bit immediates to survive unblinded into JIT-compiled native code when bpf_jit_harden >= 1. The root cause is that convert_ctx_accesses() rewrites BPF_ST|BPF_MEM to BPF_ST|BPF_PROBE_MEM32 for arena pointer stores during verification, before bpf_jit_blind_constants() runs during JIT compilation. The blinding switch only matches BPF_ST|BPF_MEM (mode 0x60), not BPF_ST|BPF_PROBE_MEM32 (mode 0xa0). The instruction falls through unblinded. Add BPF_ST|BPF_PROBE_MEM32 cases to bpf_jit_blind_insn() alongside the existing BPF_ST|BPF_MEM cases. The blinding transformation is identical: load the blinded immediate into BPF_REG_AX via mov+xor, then convert the immediate store to a register store (BPF_STX). The rewritten STX instruction must preserve the BPF_PROBE_MEM32 mode so the architecture JIT emits the correct arena addressing (R12-based on x86-64). Cannot use the BPF_STX_MEM() macro here because it hardcodes BPF_MEM mode; construct the instruction directly instead.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.11-1 (sid)linux 6.19.11-1 (sid)
linuxlinux
linuxlinux>= 6082b6c328b5486da2b356eae94b8b83c98b5565 < 56af722756ed82fee2ae5d5b4d0474340750619556af722756ed82fee2ae5d5b4d04743407506195
linuxlinux>= 6082b6c328b5486da2b356eae94b8b83c98b5565 < ccbf29b28b5554f9d65b2fb53b994673ad58b3bfccbf29b28b5554f9d65b2fb53b994673ad58b3bf
linuxlinux>= 6082b6c328b5486da2b356eae94b8b83c98b5565 < de641ea08f8fff6906e169d2576c2ac54e562fbbde641ea08f8fff6906e169d2576c2ac54e562fbb
linuxlinux>= 6082b6c328b5486da2b356eae94b8b83c98b5565 < 2321a9596d2260310267622e0ad8fbfa6f95378f2321a9596d2260310267622e0ad8fbfa6f95378f
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 6.13 < 6.18.216.18.21
linuxlinux_kernel>= 6.19 < 6.19.116.19.11
linuxlinux_kernel>= 6.9.1 < 6.12.806.12.80

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.