CVE-2026-53092CWE-393

CVE-2026-53092

High · published June 24, 2026

CVSS v3.1
7.8
EPSS
0%
Percentile
3.0
In the wild
Unconfirmed
What it is

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix linked reg delta tracking when src_reg == dst_reg

Consider the case of rX += rX where src_reg and dst_reg are pointers to

the same bpf_reg_state in adjust_reg_min_max_vals(). The latter first

modifies the dst_reg in-place, and later in the delta tracking, the

subsequent is_reg_const(src_reg)/reg_const_value(src_reg) reads the

post-{add,sub} value instead of the original source.

This is problematic since it sets an incorrect delta, which sync_linked_regs()

then propagates to linked registers, thus creating a verifier-vs-runtime

mismatch. Fix it by just skipping this corner case.

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00131 · 3.0th percentile
Weakness
CWE-393 · Return of Wrong Status Code
Published
2026-06-24T21:17Z
Affected products (2)
ProductVersionsFixed in
linux/linux_kernel≥ 6.11, < 6.18.336.18.33
linux/linux_kernel≥ 6.19, < 7.0.107.0.10
References (7)
EPSS history
Timeline
  • 24 JUN 16:30Z
    bpf: Fix linked reg delta tracking when src_reg == dst_reg
    cvelistv5