bpf: Prevent decl_tag from being referenced in func_proto arg
Published Dec 30, 2025
3.3
LOWCVSS 3.1
EPSS 0.20%
Description
Syzkaller managed to hit another decl_tag issue:
btf_func_proto_check kernel/bpf/btf.c:4506 [inline] btf_check_all_types kernel/bpf/btf.c:4734 [inline] btf_parse_type_sec+0x1175/0x1980 kernel/bpf/btf.c:4763 btf_parse kernel/bpf/btf.c:5042 [inline] btf_new_fd+0x65a/0xb00 kernel/bpf/btf.c:6709 bpf_btf_load+0x6f/0x90 kernel/bpf/syscall.c:4342 __sys_bpf+0x50a/0x6c0 kernel/bpf/syscall.c:5034 __do_sys_bpf kernel/bpf/syscall.c:5093 [inline] __se_sys_bpf kernel/bpf/syscall.c:5091 [inline] __x64_sys_bpf+0x7c/0x90 kernel/bpf/syscall.c:5091 do_syscall_64+0x54/0x70 arch/x86/entry/common.c:48
This seems similar to commit ea68376c8bed ("bpf: prevent decl_tag from being referenced in func_proto") but for the argument.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.16StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.16
- Version 6.0.16StatusunaffectedConstraints<=6.0.*
- Version 6.1.2StatusunaffectedConstraints<=6.1.*
- Version 6.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Exploiting this requires the ability to load BPF programs, which needs CAP_BPF or CAP_SYS_ADMIN. The impact is limited to causing BTF parsing issues rather than direct code execution.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-50883 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2426204 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-55913 Advisory
- https://git.kernel.org/stable/c/3f3d54962a032581996edda8e6bcbf7a30371234
- https://git.kernel.org/stable/c/e6d276dcc9204f95632580c43d66c52ca502d7ec
- https://git.kernel.org/stable/c/f17472d4599697d701aa239b4c475a506bccfd19
- https://lore.kernel.org/linux-cve-announce/2025123025-CVE-2022-50883-09fa@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-50883
- https://www.cve.org/CVERecord?id=CVE-2022-50883
Change history (0)
No recorded changes yet.