Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-53090

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/06/2026
Última modificación:
23/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> bpf: Fix ld_{abs,ind} failure path analysis in subprogs<br /> <br /> Usage of ld_{abs,ind} instructions got extended into subprogs some time<br /> ago via commit 09b28d76eac4 ("bpf: Add abnormal return checks."). These<br /> are only allowed in subprograms when the latter are BTF annotated and<br /> have scalar return types.<br /> <br /> The code generator in bpf_gen_ld_abs() has an abnormal exit path (r0=0 +<br /> exit) from legacy cBPF times. While the enforcement is on scalar return<br /> types, the verifier must also simulate the path of abnormal exit if the<br /> packet data load via ld_{abs,ind} failed.<br /> <br /> This is currently not the case. Fix it by having the verifier simulate<br /> both success and failure paths, and extend it in similar ways as we do<br /> for tail calls. The success path (r0=unknown, continue to next insn) is<br /> pushed onto stack for later validation and the r0=0 and return to the<br /> caller is done on the fall-through side.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.10 (incluyendo) 7.0.10 (excluyendo)