๐Ÿ” CVE Alert

CVE-2026-92485

UNKNOWN 0.0

bpf: Fix WARNING in bpf_tracing_link_release

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix WARNING in bpf_tracing_link_release The trampoline could be corrupted by the blindly 'tr->flags = BPF_TRAMP_F_TAIL_CALL_CTX' in verifier. 1. A fexit attached to a tail_call_reachable prog. 'tr->flags' became 'BPF_TRAMP_F_CALL_ORIG | BPF_TRAMP_F_TAIL_CALL_CTX'. And, the trampoline would poke the target prog's nop insn using jmp insn instead of call insn. 2. Another fexit loaded with the same tail_call_reachable prog target. 'tr->flags' became 'BPF_TRAMP_F_TAIL_CALL_CTX'. 3. Close the first fexit link. Due to no BPF_TRAMP_F_CALL_ORIG in 'tr->flags', the trampoline will fail to restore the prog's nop insn using call insn. [ 3.410719] WARNING: kernel/bpf/syscall.c:3551 at bpf_tracing_link_release+0x53/0x60, CPU#1: test_progs/98 ... [ 3.428793] bpf_link_free+0x58/0x130 [ 3.429293] bpf_link_release+0x23/0x30 Fix the warning by updating 'tr->flags' with '|=' and lock.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
2b5dcb31a19a2e0acd869b12c9db9b2d696ef544 < 48a0209d8da0d90a7b0a0db19d1ff88027b13781 2b5dcb31a19a2e0acd869b12c9db9b2d696ef544 < 61aaa8782bec59ecffd22e030f54ef9351bcabf9 605c8d8f9966fcd2f0b858fabebe416fc83f2209 028480eaf2a1401e914a1fa1a4a21d877cf0ae30 8f873cc3f67f2257493063e57d0caf07ef889ee9 6.1.72 < 6.2 6.5.12 < 6.6 6.6.2 < 6.7
Linux / Linux
6.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/48a0209d8da0d90a7b0a0db19d1ff88027b13781 git.kernel.org: https://git.kernel.org/stable/c/61aaa8782bec59ecffd22e030f54ef9351bcabf9