CVE-2026-53096
published 2026-06-24CVE-2026-53096: In the Linux kernel, the following vulnerability has been resolved: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path The DEVMAP_HASH branch in…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
3.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path
The DEVMAP_HASH branch in dev_map_redirect_multi() uses
hlist_for_each_entry_safe() to iterate hash buckets, but this function
runs under RCU protection (called from xdp_do_generic_redirect_map()
in softirq context). Concurrent writers (__dev_map_hash_update_elem,
dev_map_hash_delete_elem) modify the list using RCU primitives
(hlist_add_head_rcu, hlist_del_rcu).
hlist_for_each_entry_safe() performs plain pointer dereferences without
rcu_dereference(), missing the acquire barrier needed to pair with
writers' rcu_assign_pointer(). On weakly-ordered architectures (ARM64,
POWER), a reader can observe a partially-constructed node. It also
defeats CONFIG_PROVE_RCU lockdep validation and KCSAN data-race
detection.
Replace with hlist_for_each_entry_rcu() using rcu_read_lock_bh_held()
as the lockdep condition, consistent with the rcu_dereference_check()
used in the DEVMAP (non-hash) branch of the same functions. Also fix
the same incorrect lockdep_is_held(&dtab->index_lock) condition in
dev_map_enqueue_multi(), where the lock is not held either.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= e624d4ed4aa8cc3c69d1359b0aaea539203ed266 < 4a3d0fe30b907ff324b1b49756f7e713d67f3645 | 4a3d0fe30b907ff324b1b49756f7e713d67f3645 |
| linux | linux | >= e624d4ed4aa8cc3c69d1359b0aaea539203ed266 < b089aa6e94d7a08e74d076a0fe274842dc9feccc | b089aa6e94d7a08e74d076a0fe274842dc9feccc |
| linux | linux | >= e624d4ed4aa8cc3c69d1359b0aaea539203ed266 < 571a05ea1baaccc0dc1e0d227b2cbc978b96d392 | 571a05ea1baaccc0dc1e0d227b2cbc978b96d392 |
| linux | linux | >= e624d4ed4aa8cc3c69d1359b0aaea539203ed266 < cb2c1f3cf65b855548e1b8d55a08bfbaa5a0901a | cb2c1f3cf65b855548e1b8d55a08bfbaa5a0901a |
| linux | linux | >= e624d4ed4aa8cc3c69d1359b0aaea539203ed266 < d4c4bd231ebad70e6f30db429e9640bf378b2f52 | d4c4bd231ebad70e6f30db429e9640bf378b2f52 |
| linux | linux | >= e624d4ed4aa8cc3c69d1359b0aaea539203ed266 < 7027e705062482a8cea43a1c13ede3c35653966f | 7027e705062482a8cea43a1c13ede3c35653966f |
| linux | linux | >= e624d4ed4aa8cc3c69d1359b0aaea539203ed266 < 8ed82f807bb09d2c8455aaa665f2c6cb17bc6a19 | 8ed82f807bb09d2c8455aaa665f2c6cb17bc6a19 |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 7.0.9 bpf dev_map_redirect_multi index_lock privilege escalation (WID-SEC-2026-2077)
vuldb·2026-06-28
CVE-2026-53096 [LOW] Linux Kernel up to 7.0.9 bpf dev_map_redirect_multi index_lock privilege escalation (WID-SEC-2026-2077)
A vulnerability was found in Linux Kernel up to 7.0.9. It has been classified as problematic. Affected by this issue is the function dev_map_redirect_multi of the component bpf. The manipulation of the argument index_lock leads to privilege escalation.
This vulnerability is referenced as CVE-2026-53096. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is recommended.
GHSA
In the Linux kernel, the following vulnerability has been resolved: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path The DEVMAP_HASH branch in dev_map_redirect_multi() uses hlist_for
ghsa_unreviewed·2026-06-24
CVE-2026-53096 In the Linux kernel, the following vulnerability has been resolved: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path The DEVMAP_HASH branch in dev_map_redirect_multi() uses hlist_for
In the Linux kernel, the following vulnerability has been resolved:
bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path
The DEVMAP_HASH branch in dev_map_redirect_multi() uses
hlist_for_each_entry_safe() to iterate hash buckets, but this function
runs under RCU protection (called from xdp_do_generic_redirect_map()
in softirq context). Concurrent writers (__dev_map_hash_update_elem,
dev_map_hash_delete_elem) modify the list using RCU primitives
(hlist_add_head_rcu, hlist_del_rcu).
hlist_for_each_entry_safe() performs plain pointer dereferences without
rcu_dereference(), missing the acquire barrier needed to pair with
writers' rcu_assign_pointer(). On weakly-ordered architectures (ARM64,
POWER), a reader can observe a partially-constructed node. It also
defeats CONFIG_PROVE_R
Red Hat
kernel: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path
vendor_redhat·2026-06-24·CVSS 5.5
CVE-2026-53096 [MEDIUM] CWE-821 kernel: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path
kernel: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path
A flaw was found in the Linux kernel's BPF (Berkeley Packet Filter) component, specifically within the `dev_map_redirect_multi()` function. This vulnerability arises from an incorrect iteration method in an RCU (Read-Copy-Update) protected context, where `hlist_for_each_entry_safe()` is used without proper RCU dereferencing. This can allow a reader on weakly-ordered architectures, such as ARM64 and POWER, to observe partially-constructed data nodes. The consequence is potential data inconsistency, which could lead to system instability or unexpected behavior.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/4a3d0fe30b907ff324b1b49756f7e713d67f3645https://git.kernel.org/stable/c/571a05ea1baaccc0dc1e0d227b2cbc978b96d392https://git.kernel.org/stable/c/7027e705062482a8cea43a1c13ede3c35653966fhttps://git.kernel.org/stable/c/8ed82f807bb09d2c8455aaa665f2c6cb17bc6a19https://git.kernel.org/stable/c/b089aa6e94d7a08e74d076a0fe274842dc9feccchttps://git.kernel.org/stable/c/cb2c1f3cf65b855548e1b8d55a08bfbaa5a0901ahttps://git.kernel.org/stable/c/d4c4bd231ebad70e6f30db429e9640bf378b2f52
2026-06-24
Published