From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F315A3E2777 for ; Sat, 22 Aug 2026 15:40:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787413260; cv=none; b=uUXZO4xmJF3K1hPTpN2T5AqlTF65jCQb64uFOcdOxU7QG3vc4jjDIEJMOnSOlXHOUNNBpwgBOO7ln82Voey/7n4xoye+2vcPnotFJDeMs1vHnhk5HC8LQvbWdx1KrOJwTi5zdoYBiD80dNFPbAwLdy3i18uuBInbS5Ci1dI6MHQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787413260; c=relaxed/simple; bh=aQNupKOEsRD2uGRzgTYZ/k1sr0RI0VR12or+4f/4SJk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=N7go8me+5gGB7LOX3bR8nxeKi58Cc7d3LhOaRZUC30Xa9Y7HBWkL8N8YYQBXSliPD7FTCUS5CnIro+GFP4UGoflXL/0P831oFPF0OpyFOJyswMnP5IHZiNU85o0GAaUgK8IpLoxnw+gSs8C7CsQq/gbd8F1TtkcK2jLYFgsEf7E= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=QFxngwd8; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="QFxngwd8" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 598A21F000E9; Sat, 22 Aug 2026 15:40:58 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1787413258; bh=I2GrshgDvlSdle6IW9qAdpYtsOcg7qjTtODoH+00PhQ=; h=From:To:Cc:Subject:Date:Reply-To; b=QFxngwd8o/Hgn5ChvnM7l6yQ7/+SHj6mPfL0DHxvpbbgfEWDhgbqaVUm4B/kZ9sD9 QKgy07osq21QbLHCuBA/xayiS8IfzkggqqsOfseoku4T3yO4BKQv3AOb5DZ5NyK4yO DtecdGMvumB7i3ANbWZryRyqYhqKZhK6V6IaPW7E= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-74720: bpf: Preserve pointer state for commuted arithmetic Date: Sat, 22 Aug 2026 17:33:24 +0200 Message-ID: <2026082239-CVE-2026-74720-a11f@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3630; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=9gK0fe1guLVchHT90POP0e2eVgwhBNzn2159sonuRgw=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmdB25P3iiQ/q7Yw2nlK3vFuZuz3e9NtHi1oOvN/UYv/ wM59q++dcSyMAgyMciKKbJ82cZzdH/FIUUvQ9vTMHNYmUCGMHBxCsBEWlcyzC85UHXf5qt9edPs 3aoVa8+9U+g5msOw4Iza44WBNlOr0zJT35zP3B4cyrv1DAA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve pointer state for commuted arithmetic When scalar += pointer is handled in adjust_ptr_min_max_vals(), the destination register inherits the pointer state from the source pointer. Copying only selected fields is fragile because pointer provenance is tracked by several bpf_reg_state fields. Use the caller's temporary offset register to preserve the scalar operand while replacing the destination with the full pointer state. This preserves the frame number for PTR_TO_STACK registers and keeps parent identity fields consistent. The Linux kernel CVE team has assigned CVE-2026-74720 to this issue. Affected and fixed versions =========================== Issue introduced in 4.16 with commit f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 and fixed in 5.10.265 with commit 86b203aadc2930e0a4f9c6277b5b80ff3664c472 Issue introduced in 4.16 with commit f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 and fixed in 5.15.216 with commit 8109c25e0c41f5f19a1c2380bb49c991a877494e Issue introduced in 4.16 with commit f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 and fixed in 6.1.183 with commit d1959028190a7649b926f5867a58de5fe221b23c Issue introduced in 4.16 with commit f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 and fixed in 6.6.152 with commit 8cb23101a3fcc7432b451ea3d0f14a90711f4acf Issue introduced in 4.16 with commit f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 and fixed in 6.12.104 with commit 29c239f8dbec5ab33a61796724d189bddee6cd4b Issue introduced in 4.16 with commit f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 and fixed in 6.18.45 with commit db6382ed3361bdd8129572a3423956cba1dae829 Issue introduced in 4.16 with commit f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 and fixed in 7.1.9 with commit eaffa1495e4fe6330aeff9f323ea3d48b01f118a Issue introduced in 4.16 with commit f4d7e40a5b7157e1329c3c5b10f60d8289fc2941 and fixed in 7.2 with commit a4c6f804b44c5c790269b25e0e61cf4e9f117c86 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74720 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: kernel/bpf/verifier.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/86b203aadc2930e0a4f9c6277b5b80ff3664c472 https://git.kernel.org/stable/c/8109c25e0c41f5f19a1c2380bb49c991a877494e https://git.kernel.org/stable/c/d1959028190a7649b926f5867a58de5fe221b23c https://git.kernel.org/stable/c/8cb23101a3fcc7432b451ea3d0f14a90711f4acf https://git.kernel.org/stable/c/29c239f8dbec5ab33a61796724d189bddee6cd4b https://git.kernel.org/stable/c/db6382ed3361bdd8129572a3423956cba1dae829 https://git.kernel.org/stable/c/eaffa1495e4fe6330aeff9f323ea3d48b01f118a https://git.kernel.org/stable/c/a4c6f804b44c5c790269b25e0e61cf4e9f117c86