CVE-2026-72426

Source
https://cve.org/CVERecord?id=CVE-2026-72426
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72426.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72426
Downstream
Published
2026-08-15T05:56:43.575Z
Modified
2026-08-16T03:48:41.440678814Z
Summary
bpf: Preserve pointer spill metadata during half-slot cleanup
Details

In the Linux kernel, the following vulnerability has been resolved:

bpf: Preserve pointer spill metadata during half-slot cleanup

__cleanfuncstate() cleans dead stack slots in 4-byte halves. When the high half of a STACKSPILL slot is dead and the low half remains live, cleanup converts the live low half to STACKMISC or STACKZERO and clears the saved spilledptr metadata.

That conversion is safe only for scalar spills. For a pointer spill, this metadata clear lets a later 32-bit fill from the still-live half avoid the normal non-scalar register-fill check and be treated as an ordinary scalar stack read.

Leave non-scalar spill slots intact in this half-live shape. This is conservative for pruning and preserves the existing checkstackreadfixedoff() rejection path for partial fills from pointer spills.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72426.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
be23266b4a08540aa43d8503a2ea10247c8daebe
Fixed
0f9278b22cda6fd2525049930157b79b4036b4ef
Fixed
3a354149bceacadbcf7d7b4766f5ef26a85892ab

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72426.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.1.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72426.json"