CVE-2026-72427
CVE CVE-2026-72427EUVD EUVD-2026-59326Veröffentlicht 2026-08-15T05:56:44.000ZZuletzt geändert 2026-08-17T05:44:07.000ZCVSS 7.8
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix effective prog array index with BPF_F_PREORDER replace_effective_prog() and purge_effective_progs() located the slot in the effective array by walking the program hlist and counting entries linearly. That count does not match the array layout: compute_effective_ progs() places BPF_F_PREORDER programs at the front (ancestor cgroup first, attach order within a cgroup) and the rest after them (descendant cgroup first). So when a preorder program is present, the linear hlist position no longer equals the program's index in the effective array. For replace_effective_prog() (bpf_link_update()) this overwrote the wrong slot, corrupting the effective order. For purge_effective_progs(), it could dummy out a slot belonging to a different program and leave the detached program in the array while bpf_prog_put() drops its reference, i.e. a use-after-free. Fix both by replaying compute_effective_progs()'s placement (including the per-cgroup preorder reversal) in a shared effective_prog_pos() helper. Identify the entry by its struct bpf_prog_list pointer rather than by (prog, link) value, so the lookup resolves to exactly the attachment the syscall selected even when the same bpf_prog is attached to several cgroups in the hierarchy.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux 555c0b713ca83968d3c843cb15485b9ba3367b1b <41b4320b84fdafe1ab586b06453d30d50415db59; 6.12.31 <6.12.97; patch: 6.12.97; 4b82b181a26cff8bf7adc3a85a88d121d92edeaf <9697db03e010391c55ae75192cbdf30c5a72c114; 6.6.93 <6.6.145; 6.15; patch: 0; patch: 7.1.5; patch: 6.18.40; 4b82b181a26cff8bf7adc3a85a88d121d92edeaf <f08aaee3152d0dfc578b3f2586932d82062701dd; 6.14.9 <6.15; patch: 6.6.145; patch: 7.2; 4707ad649cf662add3058bff47430817811b048d; 4b82b181a26cff8bf7adc3a85a88d121d92edeaf <b584f107ab90222bd825dcb4c5977326ff684109; bc8023ef3b11410682e5d4990e05e5bc2d3e1c94 <525e408c27ae714e538b8c608c3a974df3ab6c92
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.