bpf: Allow LPM map access from sleepable BPF programs
Published Jul 25, 2026
7.8
HIGHCVSS 3.1
EPSS 0.13%
Description
trie_lookup_elem() annotates its rcu_dereference_check() walks with only rcu_read_lock_bh_held(). Because rcu_dereference_check(p, c) resolves to "c || rcu_read_lock_held()", this passes for XDP/NAPI and classic RCU readers but fails for sleepable BPF programs, which enter via __bpf_prog_enter_sleepable() and hold only rcu_read_lock_trace().
trie_update_elem() and trie_delete_elem() have the same problem in a different form: they walk the trie with plain rcu_dereference(), which asserts rcu_read_lock_held() unconditionally. Both are reachable from sleepable BPF programs via the bpf_map_update_elem / bpf_map_delete_elem helpers, and from the syscall path under classic rcu_read_lock(). In the writer paths the trie is actually protected by trie->lock (an rqspinlock taken across the walk); we never relied on the RCU read-side lock to keep nodes alive there.
A sleepable LSM hook that ends up touching an LPM trie therefore triggers lockdep on debug kernels:
============================= WARNING: suspicious RCU usage 7.1.0-... Tainted: G E ----------------------------- kernel/bpf/lpm_trie.c:249 suspicious rcu_dereference_check() usage! 1 lock held by net_tests/540: #0: (rcu_tasks_trace_srcu_struct){....}-{0:0}, at: __bpf_prog_enter_sleepable+0x26/0x280 Call Trace: dump_stack_lvl lockdep_rcu_suspicious trie_lookup_elem bpf_prog_..._enforce_security_socket_connect bpf_trampoline_... security_socket_connect __sys_connect do_syscall_64
This is lockdep-only -- no UAF, since Tasks Trace RCU does serialize against the trie's reclaim path -- but it spams the console once per distinct callsite on every debug kernel running a sleepable BPF LSM that touches an LPM trie, which is increasingly common.
For the lookup path, switch the rcu_dereference_check() annotation from rcu_read_lock_bh_held() to bpf_rcu_lock_held(), which accepts all three contexts (classic, BH, Tasks Trace). Other map types already follow this convention.
For trie_update_elem() and trie_delete_elem(), annotate the walks as rcu_dereference_protected(*p, 1) -- matching trie_free() in the same file -- since trie->lock is held across the walk. rqspinlock has no lockdep_map, so the predicate degenerates to '1' rather than lockdep_is_held(&trie->lock); the protection is real but not machine-verifiable. trie_get_next_key() also uses bare rcu_dereference() but is reachable only from the BPF syscall, which holds classic rcu_read_lock() before dispatching, so it is left untouched.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.14StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.14
- Version 5.15.212StatusunaffectedConstraints<=5.15.*
- Version 6.1.178StatusunaffectedConstraints<=6.1.*
- Version 6.12.97StatusunaffectedConstraints<=6.12.*
- Version 6.18.40StatusunaffectedConstraints<=6.18.*
- Version 6.6.145StatusunaffectedConstraints<=6.6.*
- Version 7.1.4StatusunaffectedConstraints<=7.1.*
- Version 7.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.14 · < 5.15.212
- ≥ 5.16 · < 6.1.178
- ≥ 6.2 · < 6.6.145
- ≥ 6.7 · < 6.12.97
- ≥ 6.13 · < 6.18.40
- ≥ 6.19 · < 7.1.4
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- https://access.redhat.com/security/cve/CVE-2026-64352 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2507244 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48896 Advisory
- https://git.kernel.org/stable/c/2f884d371fafea137afea504d49ee4a7c8d7985b Patch
- https://git.kernel.org/stable/c/304ca50582f0c047370f85e13caec456f78c9fcc Patch
- https://git.kernel.org/stable/c/57454944737f3ad9a8703aecbbb79713b513a94b Patch
- https://git.kernel.org/stable/c/9bfdf4b81b0e56d47bc6c46c34a46638be716695 Patch
- https://git.kernel.org/stable/c/bd6ad9a6b30498d845413e863fb95c6fab3babe3 Patch
- https://git.kernel.org/stable/c/ec662a8b2cde01e76b37ccd4b992d0342299e69c Patch
- https://git.kernel.org/stable/c/f0967d4f1ba4323a3cb7dc8fdba74dd3a8caaf04 Patch
- https://lore.kernel.org/linux-cve-announce/2026072518-CVE-2026-64352-f0f9@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-64352
- https://www.cve.org/CVERecord?id=CVE-2026-64352
Change history (0)
No recorded changes yet.