CVE-2026-98376 Linux 内核 BPF 越界访问漏洞
影响攻击者可触发越界读取,可能导致内核信息泄露或崩溃
Linux 内核 BPF 子系统中,percpu_array_map_ops.map_meta_equal 指向了通用的 bpf_map_meta_equal(),该函数未比较 max_entries。当 percpu array 作为内层 map 被替换为 max_entries 更小的 map 时,可绕过大小检查。
影响范围
受影响范围为存在该缺陷的 Linux 内核版本,具体版本范围暂无公开信息。
漏洞详情
漏洞类型为越界访问。percpu_array_map_gen_lookup() 会将原始模板的 index_mask 作为 JIT 立即数内联,替换后的 map 若 max_entries 更小,查找时可能越界访问 pptrs[] 数组。修复方式是将 percpu_array_map_ops.map_meta_equal 指向 array_map_meta_equal(),后者已强制校验 max_entries 相等。
利用条件与风险
利用需具备加载 BPF 程序并操作 map-in-map 的权限,实战中可能导致内核信息泄露或系统崩溃。
修复建议
官方修复为将 percpu_array_map_ops.map_meta_equal 改为指向 array_map_meta_equal(),并新增自测用例验证不同大小替换被拒绝;建议升级至包含该补丁的内核版本。
In the Linux kernel, the following vulnerability has been resolved:
bpf: Use array_map_meta_equal for percpu array inner map replacement
percpu_array_map_ops.map_meta_equal points to the generic
bpf_map_meta_equal(), which does not compare max_entries. When a
percpu array serves as an inner map, replacing it with one that has
fewer max_entries bypasses the check. Since percpu_array_map_gen_lookup()
inlines the original template’s index_mask as a JIT immediate, a lookup
on the replacement map can access pptrs[] out of bounds.
Point percpu_array_map_ops.map_meta_equal to array_map_meta_equal(),
which already enforces the max_entries equality check.
Add a selftest to verify that replacing a percpu array inner map with
a differently-sized one is rejected.