CVE-2026-74382
CVE CVE-2026-74382EUVD EUVD-2026-59529Veröffentlicht 2026-08-15T05:58:59.000ZZuletzt geändert 2026-08-17T05:18:20.000Z
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_bpf: prevent unbounded recursion in offload rollback Quan Sun reported [1] a stack overflow in cls_bpf_offload_cmd(). Reproducer on netdevsim: add a skip_sw cls_bpf filter, set the bpf_tc_accept debugfs knob to 0, then `tc filter replace`. The replace calls tc_setup_cb_replace() which fails. cls_bpf_offload_cmd() then swaps prog/oldprog and recursively calls itself to roll back. But bpf_tc_accept=0 makes the rollback fail too, which triggers yet another rollback frame with the same arguments, and so on until the stack is exhausted. bpf_tc_accept is just a convenient knob for the reproducer. Any driver whose tc_setup_cb_replace() fails twice in a row can hit the same loop, so this is not a netdevsim-only issue. Two ways to fix it: 1) Have the rollback call tc_setup_cb_add() on oldprog instead of re-entering cls_bpf_offload_cmd(). 2) Mark the rollback frame with a flag and skip a second-level rollback from inside it. Go with (2). It is the smaller change and keeps the original behaviour: the rollback still goes through tc_setup_cb_replace(), so the driver gets one real chance to restore its state. If that attempt also fails, we just return the original error instead of recursing. [1]: https://lore.kernel.org/bpf/ce5a6005-3c5e-4696-9e05-eba9461dc860@std.uestc.edu.cn/T/#u
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux 102740bd9436a3a6ba129af3a48271d794009fa5 <e2d3b7bab3748c811dc5750ce9a8d62bc7f90ed7; 102740bd9436a3a6ba129af3a48271d794009fa5 <10753da2d659dd425a6e620f47f86852d604f67f; 102740bd9436a3a6ba129af3a48271d794009fa5 <4a76953c3ed043797e81529b9395e9ca6f4c7609; patch: 5.15.212; 4.15; patch: 0; 102740bd9436a3a6ba129af3a48271d794009fa5 <33373e1f378a501bc51aa73312f74295c84e3101; patch: 6.1.178; 102740bd9436a3a6ba129af3a48271d794009fa5 <1387f252a242a51bfbb6eace29c8f8db21b457da; 102740bd9436a3a6ba129af3a48271d794009fa5 <3fa6fb5d771c992ebedbfa7331c6bcc6f33f89b7; patch: 6.18.40; patch: 6.12.97; 102740bd9436a3a6ba129af3a48271d794009fa5 <a018f208ab7512380bd4cf670064d48cba00a1b1; 102740bd9436a3a6ba129af3a48271d794009fa5 <27db54b90bcc7c37867fe664107fa25ea6a116e4; patch: 7.1.5; patch: 5.10.261; patch: 7.2; patch: 6.6.145
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.