Back

bpf: Reject negative optlen in cgroup getsockopt hook

Published Sep 17, 2026

Description

A cgroup getsockopt BPF program can shrink ctx->optlen after the kernel getsockopt handler has run. The kernel-buffer variant, used by TCP_ZEROCOPY_RECEIVE, only rejects values larger than the original length.

If BPF writes a negative optlen, that value is accepted and propagated back to the TCP getsockopt code. It can then be passed to copy_to_sockptr() as a size_t and trigger the hardened usercopy bytes > INT_MAX warning.

Reject negative ctx.optlen in __cgroup_bpf_run_filter_getsockopt_kern(), matching the lower-bound validation already present in the sockptr-based getsockopt hook.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Sep 17, 2026
Updated Sep 17, 2026
Reserved Sep 11, 2026
NVD
Status Received
Modified Sep 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Linux
Published Sep 17, 2026
Updated Sep 17, 2026
Exploited since n/a
EUVD-2026-81750