From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 59F5550C29E for ; Fri, 4 Sep 2026 16:52:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788540775; cv=none; b=HFVQpYCRHXVKVRnPmJZF8NF55WylvS2b6vCSva1LlJOnE+D7Y31uA+W8WXtxPd4afpDsKvevwvUv78a8lMJaRMiAxj/6hO3SK3ibjOO5RTU0DQHnOs2vdCBM2HrR5x/hevp0NfNluggMzj8K9gHPgK21mzIO9jv90PqafyxJe5A= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788540775; c=relaxed/simple; bh=HK+ouLDOxwaogafOzpJbxwwYhKM3Y8gtZDUYiSa2ChA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=mdmRSqTkseLV9rMTc3EKF1Z3ykkfM51ftzKSpc8DJTY3UPDWHmV+O/rJGyeJNwpcYiItXtxtXQT/Sg1EX0ex/oqKK/BXVUQvGc0Pf0y7h/lwFoPSKVOJzfrRbftEUFSAFZ1U+BQ0ZGD+uUCfS9HYat7cORGW01T9k6epLCciIwE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=qnBftdxV; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="qnBftdxV" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 8E91E1F00A3D; Fri, 4 Sep 2026 16:52:52 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788540773; bh=FsPajdUIHVTSnTR/lBkKVQmRTJLYHBN9ILlGFZbp4PY=; h=From:To:Cc:Subject:Date:Reply-To; b=qnBftdxVQ6glHLnfHy6ah/OkiMo/awkFk1TEb84EmhoY5ER+GOFvyo9m1SauJxTn0 qrZur19BhE+qo6e8KiWN1M0FexnIjCQBBlJbttEBCM9FbW4iR0LM5FPCrklqdoX4oX SS4kyUf83J3iaF0XiJmdAk/2nsGu+zjugCffg1m0= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80865: bpf: Add missing access_ok call to copy_user_syms Date: Fri, 4 Sep 2026 18:46:32 +0200 Message-ID: <2026090431-CVE-2026-80865-ed5a@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3057; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=i8AnWMXswpI/YYCRVG+x9Rp4rFrpcGaO9j1jvZ0fnE8=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmzvj6PMrX4rPpNrNtz2qyQG11Gx5hKNx1rfbT+6ER+W wMzhvVeHbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAjARVQ+G+bVv/zm/Tk/SZZjy 1GqHIrfLhYD+TQzzo7cHP3C7/bjvs/2ZR5ELzpiX9BjOBgA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: bpf: Add missing access_ok call to copy_user_syms As reported by sashiko we use __get_user without prior access_ok call on the user space pointer. Adding the missing call for the whole pointer array. Plus removing the err check in the error path, because it's not needed and also we can return -ENOMEM directly from the first kvmalloc_array fail path. [1] https://lore.kernel.org/bpf/20260611115503.AC16D1F00893@smtp.kernel.org/ The Linux kernel CVE team has assigned CVE-2026-80865 to this issue. Affected and fixed versions =========================== Issue introduced in 5.19 with commit 0236fec57a15dc2a068dfe4488e0c2ab4559b1ec and fixed in 6.1.178 with commit a67f7f9647cb243b3be32163e88e5bc76e3d51e9 Issue introduced in 5.19 with commit 0236fec57a15dc2a068dfe4488e0c2ab4559b1ec and fixed in 6.6.145 with commit 8b719cef5ac30ab83ce5693c5faf10e4944874af Issue introduced in 5.19 with commit 0236fec57a15dc2a068dfe4488e0c2ab4559b1ec and fixed in 6.12.97 with commit 128391b57e0977c35243672a6f970073651f3831 Issue introduced in 5.19 with commit 0236fec57a15dc2a068dfe4488e0c2ab4559b1ec and fixed in 6.18.40 with commit 0b6252afcd1965f77c6a6f8a802a2e1381822b98 Issue introduced in 5.19 with commit 0236fec57a15dc2a068dfe4488e0c2ab4559b1ec and fixed in 7.1.5 with commit 28ce7bcf8a29aa395b60764df4c97be745de89d0 Issue introduced in 5.19 with commit 0236fec57a15dc2a068dfe4488e0c2ab4559b1ec and fixed in 7.2 with commit d5dc200c3a3f217de072af269dd90adddf90e48d Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80865 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: kernel/trace/bpf_trace.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/a67f7f9647cb243b3be32163e88e5bc76e3d51e9 https://git.kernel.org/stable/c/8b719cef5ac30ab83ce5693c5faf10e4944874af https://git.kernel.org/stable/c/128391b57e0977c35243672a6f970073651f3831 https://git.kernel.org/stable/c/0b6252afcd1965f77c6a6f8a802a2e1381822b98 https://git.kernel.org/stable/c/28ce7bcf8a29aa395b60764df4c97be745de89d0 https://git.kernel.org/stable/c/d5dc200c3a3f217de072af269dd90adddf90e48d