In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject BPFMAPTYPEINODESTORAGE creation if BPF LSM is uninitialized
When CONFIGBPFLSM=y is set, BPF inode storage maps (BPFMAPTYPEINODESTORAGE) are compiled into the kernel. However, if the BPF LSM is not explicitly enabled at boot time (e.g. omitted from the "lsm=" boot parameter), lsm_prepare() is never executed for the BPF LSM.
Consequently, the BPF inode security blob offset (bpflsmblobsizes.lbsinode) is never initialized and remains at its default compiled size of 8 bytes instead of being updated to a valid offset past the reserved struct rcu_head (typically 16 bytes or more).
When a privileged user creates and updates a BPFMAPTYPEINODESTORAGE map, bpfinode() evaluates inode->isecurity + 8. This erroneously aliases the struct rcuhead.func callback pointer at the beginning of the inode->isecurity blob. During subsequent map element cleanup or inode destruction, writing NULL to ownerstorage clears the queued RCU callback pointer. When rcudo_batch() later executes the queued callback, it attempts an instruction fetch at address 0x0, triggering an immediate kernel panic.
Fix this by introducing a global bpflsminitialized boolean flag marked with _roafterinit. Set this flag to true inside bpflsminit() when the LSM framework successfully registers the BPF LSM. Gate map allocation in inodestoragemapalloc() on this flag, returning -EOPNOTSUPP if the BPF LSM is in turn uninitialized.
This fail-fast approach prevents userspace from allocating inode storage maps when the supporting BPF LSM infrastructure is absent, avoiding zombie map states.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64192.json",
"cna_assigner": "Linux"
}