bpf: NUL-terminate replaced sysctl value
In the Linux kernel, the following vulnerability has been resolved: bpf: NUL-terminate replaced sysctl value When writing to sysctls, proc_sys_call_handler() guarantees that the buffer passed to proc handlers is NUL-terminated. If bpf_sysctl_set_new_value() replaces the pending sysctl value, it can hand a replacement buffer directly to proc handlers. However, the helper currently copies only buf_len bytes into that buffer without appending a NUL terminator, leaving downstream parsers vulnerable to out-of-bounds access. Fix this by appending a '\0' after the replaced value to restore the expected sysctl semantics. Since the helper already rejects buf_len greater than PAGE_SIZE - 1, there is always room for the extra byte. Reproduced in a QEMU x86_64 guest booted with KASAN while exercising the sysctl replacement path with a cgroup/sysctl BPF program. The reproducer targets `/proc/sys/net/core/flow_limit_cpu_bitmap`, fills the original user write buffer with non-zero bytes, and overrides the sysctl value so the replacement buffer lacks a terminating NUL. Under that setup, the pre-fix kernel reported: BUG: KASAN: slab-out-of-bounds in strnchrnul+0x72/0x90 Read of size 1 at addr ffff88800de57000 by task repro_patch3/66 CPU: 0 UID: 0 PID: 66 Comm: repro_patch3 Not tainted 7.1.0-rc3-00269-g8370ca1f87cc #6 PREEMPT(lazy) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 Call Trace: <TASK> dump_stack_lvl+0x68/0xa0 print_report+0xcb/0x5e0 ? __virt_addr_valid+0x21d/0x3f0 ? strnchrnul+0x72/0x90 ? strnchrnul+0x72/0x90 kasan_report+0xca/0x100 ? strnchrnul+0x72/0x90 strnchrnul+0x72/0x90 bitmap_parse+0x37/0x2e0 flow_limit_cpu_sysctl+0xc6/0x840 ? __pfx_flow_limit_cpu_sysctl+0x10/0x10 ? __kvmalloc_node_noprof+0x5ba/0x870 proc_sys_call_handler+0x31d/0x480 ? __pfx_proc_sys_call_handler+0x10/0x10 ? selinux_file_permission+0x39f/0x500 ? lock_is_held_type+0x9e/0x120 vfs_write+0x98e/0x1000 ... </TASK> The buggy address is located 0 bytes to the right of allocated 4096-byte region [ffff88800de56000, ffff88800de57000) With this fix applied, rerunning the same sysctl-targeted path yields no corresponding KASAN reports.
- Published
- Sep 24, 2026
- Updated
- Oct 3, 2026
- EPSS
- 0.2% · 6th percentile
- CWE
- —
Sign in to follow · You’ll be notified if a followed record enters KEV, gets an exploit or is updated.
Report tools
Action score
0
Monitor
Low priority for now.
- CVSS
- 0 / 40 · —
- CISA KEV
- 0 / 30 · Not listed
- EPSS
- 0 / 30 · 0.2%
Noroxi analysis
No Noroxi analysis for this record yet
We don't hand-write analysis for the hundreds of thousands of vulnerabilities in the database; that wouldn't be honest. For notable, high-impact vulnerabilities our team writes the mechanism, detection and remediation steps.
We use this product, ask for helpAffected systems
—
Versions reported by the vendor
Affected version ranges reported by the assigning authority (Linux). Independent of NVD's CPE analysis and usually ahead of it.
Linux Linux
- 5.8affected
- 32927393dc1ccd60fb2bdc05b9e8e88753761469 and later · before bfcee1f79aaefa90679ad47690107fb7682724ecaffected · git
- 32927393dc1ccd60fb2bdc05b9e8e88753761469 and later · before c73e4a04eedc677fe91a736d7a5db45100adba5eaffected · git
- 32927393dc1ccd60fb2bdc05b9e8e88753761469 and later · before 36d3e9f62dc2beb9299d3bb6f589cb9e07f773feaffected · git
- 32927393dc1ccd60fb2bdc05b9e8e88753761469 and later · before 31377675c3d75603d957c08e338a9ac27e9f6cd5affected · git
- 32927393dc1ccd60fb2bdc05b9e8e88753761469 and later · before 76c14b10f50eb0afcc76e244562fa2d8c661e224affected · git
- 32927393dc1ccd60fb2bdc05b9e8e88753761469 and later · before 3b2814dd842a565fcf9cc370156e1ba9eae16239affected · git
- 32927393dc1ccd60fb2bdc05b9e8e88753761469 and later · before a66e3b5bacf38d6ab29fa05a9754f7a114485605affected · git
- before 5.8not affected · semver
- 5.10.271 and later · up to and including 5.10.*not affected · semver
Package-level exposure
OSV and GitHub Advisory data: ecosystem, package and range. SBOM matching uses this table.
| Ecosystem | Package | Affected range | Fix |
|---|---|---|---|
| Debian:12 | linux | all versions | — |
| Debian:12 | linux-6.12 | before 6.12.111-1~deb12u1 | 6.12.111-1~deb12u1 |
| Debian:13 | linux | before 6.12.111-1 | 6.12.111-1 |
| Debian:14 | linux | before 7.2.6-1 | 7.2.6-1 |
Same product
linux: all recordsOther highest-scoring records for the same primary product.
- CVE-2026-74705udp: fix potential use-after-free in tunnel segmentation40Plan
- CVE-2026-74612veth: fix skb length accounting after XDP frag adjustment40Plan
- CVE-2026-74475vxlan: use neigh_ha_snapshot() in route_shortcircuit()40Plan
- CVE-2026-74309vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler40Plan
- CVE-2026-74280crypto: marvell/octeontx - fix DMA cleanup using wrong loop index40Plan
- CVE-2026-74279crypto: cavium/cpt - fix DMA cleanup using wrong loop index40Plan
Remediation
Which version to upgrade to
Fix versions compiled from the vendor, package registries and Microsoft. Verify the vendor's note before upgrading.
| Product / package | Fixed version | Source |
|---|---|---|
| Linux Linux | 31377675c3d75603d957c08e338a9ac27e9f6cd5 | Vendor (CNA) |
| Linux Linux | 36d3e9f62dc2beb9299d3bb6f589cb9e07f773fe | Vendor (CNA) |
| Linux Linux | 3b2814dd842a565fcf9cc370156e1ba9eae16239 | Vendor (CNA) |
| Linux Linux | 76c14b10f50eb0afcc76e244562fa2d8c661e224 | Vendor (CNA) |
| Linux Linux | a66e3b5bacf38d6ab29fa05a9754f7a114485605 | Vendor (CNA) |
| Linux Linux | bfcee1f79aaefa90679ad47690107fb7682724ec | Vendor (CNA) |
| Linux Linux | c73e4a04eedc677fe91a736d7a5db45100adba5e | Vendor (CNA) |
| azl3 kernel 6.6.157.1-1 on Azure Linux 3.0 | Release Notes | Microsoft (MSRC) |
| debian:linux | 6.12.111-1 · Debian:13 | Package registry (OSV) |
| debian:linux-6.12 | 6.12.111-1~deb12u1 · Debian:12 | Package registry (OSV) |
Exploit status
No known public exploit
No public exploit has been observed yet. That doesn't mean you're safe, only that the bar is a little higher.
Research context
For pentesters and researchers: attack profile, score disagreement, timeline, patch commits, credits, variant and chain candidates, bug bounty scope. All derived from existing data; no exploit code.
Timeline
From publication to today: proof of concept, Metasploit module, CISA KEV and fix record. Dates are as reported by the sources.
No dated events beyond publication.
FIRST EPSS daily score; only changes of 0.01 or more are recorded (step chart).
Patch and commit links
Commit, PR and diff links among the references. A starting point for patch-diffing and variant hunting; fixes, not exploits.
No commit or PR link among the references.
Credits
All researchersFinders, reporters and analysts named in the CNA record. Click a name for that researcher’s other records.
No credits in the CNA record.
Variant candidates
Same product, same weakness class, within 18 months. If the patch missed the root cause, the sibling bug is here.
No nightly-computed relations.
Chain candidates
An authentication bypass and a privilege-requiring bug in the same product, published close together: combined they may become an unauthenticated path.
—
Bug bounty scope
No known public program.
Source: bounty-targets-data (public HackerOne, Bugcrowd, Intigriti, YesWeHack listings).
Technical details
No CVSS vector for this record, so attack conditions can't be derived.
Weakness class (CWE)
—
Attack context
MITRE CAPEC attack patterns and ATT&CK techniques for this weakness class (CWE). A starting point for detection rules and threat hunting.
MITRE has no CAPEC/ATT&CK mapping for this CWE.
Change log
- Fix✗ → ✓
For records you follow, these changes also arrive as notifications. →
References
- git.kernel.org/stable/c/31377675c3d75603d957c08e338a9ac27e9f6cd5
- git.kernel.org/stable/c/36d3e9f62dc2beb9299d3bb6f589cb9e07f773fe
- git.kernel.org/stable/c/3b2814dd842a565fcf9cc370156e1ba9eae16239
- git.kernel.org/stable/c/76c14b10f50eb0afcc76e244562fa2d8c661e224
- git.kernel.org/stable/c/a66e3b5bacf38d6ab29fa05a9754f7a114485605
- git.kernel.org/stable/c/bfcee1f79aaefa90679ad47690107fb7682724ec
- git.kernel.org/stable/c/c73e4a04eedc677fe91a736d7a5db45100adba5e
Vendor advisories and official records. Exploit/PoC links are deliberately left out.