CVE-2026-72402

Source
https://cve.org/CVERecord?id=CVE-2026-72402
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72402.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72402
Downstream
Published
2026-08-15T05:56:26.816Z
Modified
2026-08-16T03:48:53.735170709Z
Summary
bpf: Mask pseudo pointer values in verifier logs
Details

In the Linux kernel, the following vulnerability has been resolved:

bpf: Mask pseudo pointer values in verifier logs

printbpfinsn() masks ldimm64 immediates for pointer-bearing pseudo sources when pointer leaks are not allowed, but the mask only covers BPFPSEUDOMAPFD and BPFPSEUDOMAPVALUE.

BPFPSEUDOMAPIDX, BPFPSEUDOMAPIDXVALUE, and BPFPSEUDOBTFID can also be resolved to kernel pointer values before the verifier log prints the instruction. Include them in the existing pointer classification so the log prints 0x0 instead of the rewritten address.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72402.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4976b718c3551faba2c0616ef55ebeb74db1c5ca
Fixed
1c53d16b174dd9e02243fc0e85089e2aa6a0d21a
Fixed
72a85e9464a5332fb2cd7efd26d9295275ceda2d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72402.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.10.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72402.json"