๐Ÿ” CVE Alert

CVE-2026-93138

UNKNOWN 0.0

bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux bpf_get_btf_vmlinux() lazily parses the vmlinux BTF under the bpf_verifier_lock, but publishes the result through a plain store and re-checks it through a plain lockless load. Nothing orders the stores initializing the struct btf inside btf_parse_vmlinux() against the store publishing the pointer: On a weakly ordered arch, a concurrent first-time caller taking the lockless fast path could in principle observe the pointer before the parsed contents are visible. The mutex_unlock() does not help such a reader given it only synchronizes with a later acquisition of the same lock. Thus, publish the pointer with smp_store_release() and read it on the fast path with smp_load_acquire(). Acquire semantics are needed rather than a dependency-ordered READ_ONCE(): btf_parse_vmlinux() also populates globals outside the returned object (e.g. bpf_ctx_convert.t). An address dependency would only order accesses performed through the pointer and not cover other globals.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
8580ac9404f6240668a026785d7d8856f0530409 < f32a4a40bc635be25d6816da4bd91e9e58c31bf3 8580ac9404f6240668a026785d7d8856f0530409 < a7fe72d780122eb934536f1719abad445f6afdf7 8580ac9404f6240668a026785d7d8856f0530409 < e18a10b39c994f04e1ebd7f8fc042bb1ca8ad053 8580ac9404f6240668a026785d7d8856f0530409 < 978524ecfc1c539282df5858de1eec20748c6f74 8580ac9404f6240668a026785d7d8856f0530409 < eaf302628a78806f66d8224d6ba03fb4d5025de4 8580ac9404f6240668a026785d7d8856f0530409 < 2892f3f44bf865c8fb6b6c0960edec4cc91806ee 8580ac9404f6240668a026785d7d8856f0530409 < 86d11c594d60b255b526fa5260f669463fb1a063 8580ac9404f6240668a026785d7d8856f0530409 < 92863e678070f57c17c868e4bfa2441a5c61ad2b
Linux / Linux
5.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f32a4a40bc635be25d6816da4bd91e9e58c31bf3 git.kernel.org: https://git.kernel.org/stable/c/a7fe72d780122eb934536f1719abad445f6afdf7 git.kernel.org: https://git.kernel.org/stable/c/e18a10b39c994f04e1ebd7f8fc042bb1ca8ad053 git.kernel.org: https://git.kernel.org/stable/c/978524ecfc1c539282df5858de1eec20748c6f74 git.kernel.org: https://git.kernel.org/stable/c/eaf302628a78806f66d8224d6ba03fb4d5025de4 git.kernel.org: https://git.kernel.org/stable/c/2892f3f44bf865c8fb6b6c0960edec4cc91806ee git.kernel.org: https://git.kernel.org/stable/c/86d11c594d60b255b526fa5260f669463fb1a063 git.kernel.org: https://git.kernel.org/stable/c/92863e678070f57c17c868e4bfa2441a5c61ad2b