bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec()
Published May 27, 2026
7.8
HIGHCVSS 3.1
EPSS 0.18%
Description
CO-RE accessor strings are colon-separated indices that describe a path from a root BTF type to a target field, e.g. "0:1:2" walks through nested struct members. bpf_core_parse_spec() parses each component with sscanf("%d"), so negative values like -1 are silently accepted. The subsequent bounds checks (access_idx >= btf_vlen(t)) only guard the upper bound and always pass for negative values because C integer promotion converts the __u16 btf_vlen result to int, making the comparison (int)(-1) >= (int)(N) false for any positive N.
When -1 reaches btf_member_bit_offset() it gets cast to u32 0xffffffff, producing an out-of-bounds read far past the members array. A crafted BPF program with a negative CO-RE accessor on any struct that exists in vmlinux BTF (e.g. task_struct) crashes the kernel deterministically during BPF_PROG_LOAD on any system with CONFIG_DEBUG_INFO_BTF=y (default on major distributions). The bug is reachable with CAP_BPF:
BUG: unable to handle page fault for address: ffffed11818b6626 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page Oops: Oops: 0000 [#1] SMP KASAN NOPTI CPU: 0 UID: 0 PID: 85 Comm: poc Not tainted 7.0.0-rc6 #18 PREEMPT(full) RIP: 0010:bpf_core_parse_spec (tools/lib/bpf/relo_core.c:354) RAX: 00000000ffffffff Call Trace: <TASK> bpf_core_calc_relo_insn (tools/lib/bpf/relo_core.c:1321) bpf_core_apply (kernel/bpf/btf.c:9507) check_core_relo (kernel/bpf/verifier.c:19475) bpf_check (kernel/bpf/verifier.c:26031) bpf_prog_load (kernel/bpf/syscall.c:3089) __sys_bpf (kernel/bpf/syscall.c:6228) </TASK>
CO-RE accessor indices are inherently non-negative (struct member index, array element index, or enumerator index), so reject them immediately after parsing.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.4StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.4
- Version 5.10.267StatusunaffectedConstraints<=5.10.*
- Version 5.15.209StatusunaffectedConstraints<=5.15.*
- Version 6.1.175StatusunaffectedConstraints<=6.1.*
- Version 6.12.91StatusunaffectedConstraints<=6.12.*
- Version 6.18.33StatusunaffectedConstraints<=6.18.*
- Version 6.6.141StatusunaffectedConstraints<=6.6.*
- Version 7.0.10StatusunaffectedConstraints<=7.0.*
- Version 7.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.4 · < 5.15.209
- ≥ 5.16 · < 6.1.175
- ≥ 6.2 · < 6.6.141
- ≥ 6.7 · < 6.12.91
- ≥ 6.13 · < 6.18.33
- ≥ 6.19 · < 7.0.10
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
May–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.18% (0.00176) | 6.46th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.16% (0.00161) | 5.58th | v5 (v2026.06.15) |
| May 27, 2026 | 0.01% (0.00015) | 3.53th | v4 (v2025.03.14) |
References (13)
- https://access.redhat.com/security/cve/CVE-2026-45839 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2481865 Issue Tracking
- https://git.kernel.org/stable/c/1c22483a2c4bbf747787f328392ca3e68619c4dc Patch
- https://git.kernel.org/stable/c/36a9012f76ba8d9189ae56a1f8bb7c87c07a1f3a Patch
- https://git.kernel.org/stable/c/3ff85ae79e1a74baeb916b78a63d821f6d19a994 Patch
- https://git.kernel.org/stable/c/669349b4612c26b3d7aacfa99d7174681bd19223 Patch
- https://git.kernel.org/stable/c/76f2ebaf79a9ae6d0737b87f045fe769e425d78f Patch
- https://git.kernel.org/stable/c/99dbab7b5a12d8f58d5b0aa2f7a1fe656a70f4b2 Patch
- https://git.kernel.org/stable/c/a9e777f856cd2f1efc106afc7bf21aef868509d5 Patch
- https://git.kernel.org/stable/c/c8e49b79c4b48bd687706ff6e9c82638dc81ef80
- https://lore.kernel.org/linux-cve-announce/2026052712-CVE-2026-45839-44c7@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-45839
- https://www.cve.org/CVERecord?id=CVE-2026-45839
Change history (0)
No recorded changes yet.