kernel: bpf: Enforce expected_attach_type for tailcall compatibility

cve CVE-2025-40123 2 sources, 2 claims · Watch

Red Hat writes:
kernel: bpf: Enforce expected_attach_type for tailcall compatibility the claim

What it is to other things

In words only, so not counted until a person confirms one:

affectslinux/linux
NVD says “Linux · Linux”
made_bylinux
NVD says “Linux”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
conflict
NVD7.8
receipt
Source
NVD
Its words
7.8
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "include/linux/bpf.h",
              "kernel/bpf/core.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "e53a59e7cee5c1605d1ed595933098c2b69108f9",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "dc4f348952173beb8ceb15be30b249276eccb605",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "a99de19128aec0913f3d529f529fbbff5edfaff8",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "08cb3dc9d2b44f153d0bcf2cb966e4a94b5d0f32",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "f856c598080ba7ce1252867b8ecd6ad5bdaf9a6a",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "c1ad19b5d8e23123503dcaf2d4342e1b90b923ad",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "4540aed51b12bc13364149bf95f6ecef013197c0",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "include/linux/bpf.h",
              "kernel/bpf/core.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "4.17"
              },
              {
                "lessThan": "4.17",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.270",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.221",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.156",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.112",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.53",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.17.*",
                "status": "unaffected",
                "version": "6.17.3",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "6.18",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Enforce expected_attach_type for tailcall compatibility\n\nYinhao et al. recently reported:\n\n  Our fuzzer tool discovered an uninitialized pointer issue in the\n  bpf_prog_test_run_xdp() function within the Linux kernel's BPF subsystem.\n  This leads to a NULL pointer dereference when a BPF program attempts to\n  deference the txq member of struct xdp_buff object.\n\nThe test initializes two programs of BPF_PROG_TYPE_XDP: progA acts as the\nentry point for bpf_prog_test_run_xdp() and its expected_attach_type can\nneither be of be BPF_XDP_DEVMAP nor BPF_XDP_CPUMAP. progA calls into a slot\nof a tailcall map it owns. progB's expected_attach_type must be BPF_XDP_DEVMAP\nto pass xdp_is_valid_access() validation. The program returns struct xdp_md's\negress_ifindex, and the latter is only allowed to be accessed under mentioned\nexpected_attach_type. progB is then inserted into the tailcall which progA\ncalls.\n\nThe underlying issue goes beyond XDP though. Another example are programs\nof type BPF_PROG_TYPE_CGROUP_SOCK_ADDR. sock_addr_is_valid_access() as well\nas sock_addr_func_proto() have different logic depending on the programs'\nexpected_attach_type. Similarly, a program attached to BPF_CGROUP_INET4_GETPEERNAME\nshould not be allowed doing a tailcall into a program which calls bpf_bind()\nout of BPF which is only enabled for BPF_CGROUP_INET4_CONNECT.\n\nIn short, specifying expected_attach_type allows to open up additional\nfunctionality or restrictions beyond what the basic bpf_prog_type enables.\nThe use of tailcalls must not violate these constraints. Fix it by enforcing\nexpected_attach_type in __bpf_prog_map_compatible().\n\nNote that we only enforce this for tailcall maps, but not for BPF devmaps or\ncpumaps: There, the programs are invoked through dev_map_bpf_prog_run*() and\ncpu_map_bpf_prog_run*() which set up a new environment / context and therefore\nthese situations are not prone to this issue."
      }
    ],
    "id": "CVE-2025-40123",
    "lastModified": "2026-09-14T12:17:37.453",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ]
    },
    "published": "2025-11-12T11:15:41.807",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/08cb3dc9d2b44f153d0bcf2cb966e4a94b5d0f32"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/4540aed51b12bc13364149bf95f6ecef013197c0"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/a99de19128aec0913f3d529f529fbbff5edfaff8"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/c1ad19b5d8e23123503dcaf2d4342e1b90b923ad"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/dc4f348952173beb8ceb15be30b249276eccb605"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/e53a59e7cee5c1605d1ed595933098c2b69108f9"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/f856c598080ba7ce1252867b8ecd6ad5bdaf9a6a"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Deferred"
  }
}
—
Cvss
cvss
conflict
Red Hat4.4
receipt
Source
Red Hat
Its words
4.4
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-40123",
  "CWE": "CWE-843",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2414511",
  "bugzilla_description": "kernel: bpf: Enforce expected_attach_type for tailcall compatibility",
  "cvss3_score": "4.4",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-11-12T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-40123.json",
  "severity": "low"
}
—
Cwe
cwe
Red HatCWE-843
receipt
Source
Red Hat
Its words
CWE-843
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-40123",
  "CWE": "CWE-843",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2414511",
  "bugzilla_description": "kernel: bpf: Enforce expected_attach_type for tailcall compatibility",
  "cvss3_score": "4.4",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-11-12T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-40123.json",
  "severity": "low"
}
—
Product
product
NVDLinux
receipt
Source
NVD
Its words
Linux
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
2026-09-29 17:49 UTCLinux
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "include/linux/bpf.h",
              "kernel/bpf/core.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "e53a59e7cee5c1605d1ed595933098c2b69108f9",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "dc4f348952173beb8ceb15be30b249276eccb605",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "a99de19128aec0913f3d529f529fbbff5edfaff8",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "08cb3dc9d2b44f153d0bcf2cb966e4a94b5d0f32",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "f856c598080ba7ce1252867b8ecd6ad5bdaf9a6a",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "c1ad19b5d8e23123503dcaf2d4342e1b90b923ad",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "4540aed51b12bc13364149bf95f6ecef013197c0",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "include/linux/bpf.h",
              "kernel/bpf/core.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "4.17"
              },
              {
                "lessThan": "4.17",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.270",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.221",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.156",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.112",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.53",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.17.*",
                "status": "unaffected",
                "version": "6.17.3",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "6.18",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Enforce expected_attach_type for tailcall compatibility\n\nYinhao et al. recently reported:\n\n  Our fuzzer tool discovered an uninitialized pointer issue in the\n  bpf_prog_test_run_xdp() function within the Linux kernel's BPF subsystem.\n  This leads to a NULL pointer dereference when a BPF program attempts to\n  deference the txq member of struct xdp_buff object.\n\nThe test initializes two programs of BPF_PROG_TYPE_XDP: progA acts as the\nentry point for bpf_prog_test_run_xdp() and its expected_attach_type can\nneither be of be BPF_XDP_DEVMAP nor BPF_XDP_CPUMAP. progA calls into a slot\nof a tailcall map it owns. progB's expected_attach_type must be BPF_XDP_DEVMAP\nto pass xdp_is_valid_access() validation. The program returns struct xdp_md's\negress_ifindex, and the latter is only allowed to be accessed under mentioned\nexpected_attach_type. progB is then inserted into the tailcall which progA\ncalls.\n\nThe underlying issue goes beyond XDP though. Another example are programs\nof type BPF_PROG_TYPE_CGROUP_SOCK_ADDR. sock_addr_is_valid_access() as well\nas sock_addr_func_proto() have different logic depending on the programs'\nexpected_attach_type. Similarly, a program attached to BPF_CGROUP_INET4_GETPEERNAME\nshould not be allowed doing a tailcall into a program which calls bpf_bind()\nout of BPF which is only enabled for BPF_CGROUP_INET4_CONNECT.\n\nIn short, specifying expected_attach_type allows to open up additional\nfunctionality or restrictions beyond what the basic bpf_prog_type enables.\nThe use of tailcalls must not violate these constraints. Fix it by enforcing\nexpected_attach_type in __bpf_prog_map_compatible().\n\nNote that we only enforce this for tailcall maps, but not for BPF devmaps or\ncpumaps: There, the programs are invoked through dev_map_bpf_prog_run*() and\ncpu_map_bpf_prog_run*() which set up a new environment / context and therefore\nthese situations are not prone to this issue."
      }
    ],
    "id": "CVE-2025-40123",
    "lastModified": "2026-09-14T12:17:37.453",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ]
    },
    "published": "2025-11-12T11:15:41.807",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/08cb3dc9d2b44f153d0bcf2cb966e4a94b5d0f32"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/4540aed51b12bc13364149bf95f6ecef013197c0"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/a99de19128aec0913f3d529f529fbbff5edfaff8"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/c1ad19b5d8e23123503dcaf2d4342e1b90b923ad"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/dc4f348952173beb8ceb15be30b249276eccb605"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/e53a59e7cee5c1605d1ed595933098c2b69108f9"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/f856c598080ba7ce1252867b8ecd6ad5bdaf9a6a"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Deferred"
  }
}
—
Severity
severity
Red Hatlow
A flaw that is unlikely to be exploited, or whose impact is minimal.
receipt
Source
Red Hat
Its words
low
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-40123",
  "CWE": "CWE-843",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2414511",
  "bugzilla_description": "kernel: bpf: Enforce expected_attach_type for tailcall compatibility",
  "cvss3_score": "4.4",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-11-12T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-40123.json",
  "severity": "low"
}
—
Status
status
NVDDeferred
receipt
Source
NVD
Its words
Deferred
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "include/linux/bpf.h",
              "kernel/bpf/core.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "e53a59e7cee5c1605d1ed595933098c2b69108f9",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "dc4f348952173beb8ceb15be30b249276eccb605",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "a99de19128aec0913f3d529f529fbbff5edfaff8",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "08cb3dc9d2b44f153d0bcf2cb966e4a94b5d0f32",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "f856c598080ba7ce1252867b8ecd6ad5bdaf9a6a",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "c1ad19b5d8e23123503dcaf2d4342e1b90b923ad",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "4540aed51b12bc13364149bf95f6ecef013197c0",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "include/linux/bpf.h",
              "kernel/bpf/core.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "4.17"
              },
              {
                "lessThan": "4.17",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.270",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.221",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.156",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.112",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.53",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.17.*",
                "status": "unaffected",
                "version": "6.17.3",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "6.18",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Enforce expected_attach_type for tailcall compatibility\n\nYinhao et al. recently reported:\n\n  Our fuzzer tool discovered an uninitialized pointer issue in the\n  bpf_prog_test_run_xdp() function within the Linux kernel's BPF subsystem.\n  This leads to a NULL pointer dereference when a BPF program attempts to\n  deference the txq member of struct xdp_buff object.\n\nThe test initializes two programs of BPF_PROG_TYPE_XDP: progA acts as the\nentry point for bpf_prog_test_run_xdp() and its expected_attach_type can\nneither be of be BPF_XDP_DEVMAP nor BPF_XDP_CPUMAP. progA calls into a slot\nof a tailcall map it owns. progB's expected_attach_type must be BPF_XDP_DEVMAP\nto pass xdp_is_valid_access() validation. The program returns struct xdp_md's\negress_ifindex, and the latter is only allowed to be accessed under mentioned\nexpected_attach_type. progB is then inserted into the tailcall which progA\ncalls.\n\nThe underlying issue goes beyond XDP though. Another example are programs\nof type BPF_PROG_TYPE_CGROUP_SOCK_ADDR. sock_addr_is_valid_access() as well\nas sock_addr_func_proto() have different logic depending on the programs'\nexpected_attach_type. Similarly, a program attached to BPF_CGROUP_INET4_GETPEERNAME\nshould not be allowed doing a tailcall into a program which calls bpf_bind()\nout of BPF which is only enabled for BPF_CGROUP_INET4_CONNECT.\n\nIn short, specifying expected_attach_type allows to open up additional\nfunctionality or restrictions beyond what the basic bpf_prog_type enables.\nThe use of tailcalls must not violate these constraints. Fix it by enforcing\nexpected_attach_type in __bpf_prog_map_compatible().\n\nNote that we only enforce this for tailcall maps, but not for BPF devmaps or\ncpumaps: There, the programs are invoked through dev_map_bpf_prog_run*() and\ncpu_map_bpf_prog_run*() which set up a new environment / context and therefore\nthese situations are not prone to this issue."
      }
    ],
    "id": "CVE-2025-40123",
    "lastModified": "2026-09-14T12:17:37.453",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ]
    },
    "published": "2025-11-12T11:15:41.807",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/08cb3dc9d2b44f153d0bcf2cb966e4a94b5d0f32"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/4540aed51b12bc13364149bf95f6ecef013197c0"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/a99de19128aec0913f3d529f529fbbff5edfaff8"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/c1ad19b5d8e23123503dcaf2d4342e1b90b923ad"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/dc4f348952173beb8ceb15be30b249276eccb605"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/e53a59e7cee5c1605d1ed595933098c2b69108f9"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/f856c598080ba7ce1252867b8ecd6ad5bdaf9a6a"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Deferred"
  }
}
—
Vendor
vendor
NVDLinux
receipt
Source
NVD
Its words
Linux
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
2026-09-29 17:49 UTCLinux
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Linux",
            "programFiles": [
              "include/linux/bpf.h",
              "kernel/bpf/core.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "lessThan": "e53a59e7cee5c1605d1ed595933098c2b69108f9",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "dc4f348952173beb8ceb15be30b249276eccb605",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "a99de19128aec0913f3d529f529fbbff5edfaff8",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "08cb3dc9d2b44f153d0bcf2cb966e4a94b5d0f32",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "f856c598080ba7ce1252867b8ecd6ad5bdaf9a6a",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "c1ad19b5d8e23123503dcaf2d4342e1b90b923ad",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              },
              {
                "lessThan": "4540aed51b12bc13364149bf95f6ecef013197c0",
                "status": "affected",
                "version": "5e43f899b03a3492ce5fc44e8900becb04dae9c0",
                "versionType": "git"
              }
            ]
          },
          {
            "defaultStatus": "affected",
            "product": "Linux",
            "programFiles": [
              "include/linux/bpf.h",
              "kernel/bpf/core.c"
            ],
            "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
            "vendor": "Linux",
            "versions": [
              {
                "status": "affected",
                "version": "4.17"
              },
              {
                "lessThan": "4.17",
                "status": "unaffected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.10.*",
                "status": "unaffected",
                "version": "5.10.270",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "5.15.*",
                "status": "unaffected",
                "version": "5.15.221",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.1.*",
                "status": "unaffected",
                "version": "6.1.156",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.6.*",
                "status": "unaffected",
                "version": "6.6.112",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.12.*",
                "status": "unaffected",
                "version": "6.12.53",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.17.*",
                "status": "unaffected",
                "version": "6.17.3",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "6.18",
                "versionType": "original_commit_for_fix"
              }
            ]
          }
        ],
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Enforce expected_attach_type for tailcall compatibility\n\nYinhao et al. recently reported:\n\n  Our fuzzer tool discovered an uninitialized pointer issue in the\n  bpf_prog_test_run_xdp() function within the Linux kernel's BPF subsystem.\n  This leads to a NULL pointer dereference when a BPF program attempts to\n  deference the txq member of struct xdp_buff object.\n\nThe test initializes two programs of BPF_PROG_TYPE_XDP: progA acts as the\nentry point for bpf_prog_test_run_xdp() and its expected_attach_type can\nneither be of be BPF_XDP_DEVMAP nor BPF_XDP_CPUMAP. progA calls into a slot\nof a tailcall map it owns. progB's expected_attach_type must be BPF_XDP_DEVMAP\nto pass xdp_is_valid_access() validation. The program returns struct xdp_md's\negress_ifindex, and the latter is only allowed to be accessed under mentioned\nexpected_attach_type. progB is then inserted into the tailcall which progA\ncalls.\n\nThe underlying issue goes beyond XDP though. Another example are programs\nof type BPF_PROG_TYPE_CGROUP_SOCK_ADDR. sock_addr_is_valid_access() as well\nas sock_addr_func_proto() have different logic depending on the programs'\nexpected_attach_type. Similarly, a program attached to BPF_CGROUP_INET4_GETPEERNAME\nshould not be allowed doing a tailcall into a program which calls bpf_bind()\nout of BPF which is only enabled for BPF_CGROUP_INET4_CONNECT.\n\nIn short, specifying expected_attach_type allows to open up additional\nfunctionality or restrictions beyond what the basic bpf_prog_type enables.\nThe use of tailcalls must not violate these constraints. Fix it by enforcing\nexpected_attach_type in __bpf_prog_map_compatible().\n\nNote that we only enforce this for tailcall maps, but not for BPF devmaps or\ncpumaps: There, the programs are invoked through dev_map_bpf_prog_run*() and\ncpu_map_bpf_prog_run*() which set up a new environment / context and therefore\nthese situations are not prone to this issue."
      }
    ],
    "id": "CVE-2025-40123",
    "lastModified": "2026-09-14T12:17:37.453",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
          "type": "Secondary"
        }
      ]
    },
    "published": "2025-11-12T11:15:41.807",
    "references": [
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/08cb3dc9d2b44f153d0bcf2cb966e4a94b5d0f32"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/4540aed51b12bc13364149bf95f6ecef013197c0"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/a99de19128aec0913f3d529f529fbbff5edfaff8"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/c1ad19b5d8e23123503dcaf2d4342e1b90b923ad"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/dc4f348952173beb8ceb15be30b249276eccb605"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/e53a59e7cee5c1605d1ed595933098c2b69108f9"
      },
      {
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "url": "https://git.kernel.org/stable/c/f856c598080ba7ce1252867b8ecd6ad5bdaf9a6a"
      }
    ],
    "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "vulnStatus": "Deferred"
  }
}
—

vulnerability

kernel: bpf: Enforce expected_attach_type for tailcall compatibility
zetlyn/cve-redhat · 2025-11-12
cvss 4.4 cwe CWE-843 severity low source
In the Linux kernel, the following vulnerability has been resolved: bpf: Enforce expected_attach_type for tailcall compatibility Yinhao et al. recently reported: Our fuzzer tool discovered an uninitialized pointer issue in the bpf_prog_test_run_xdp() function within the Linux kernel's BPF subsystem. This leads to a NULL pointer dereference when a BPF program attempts to deference the txq member of struct xdp_buff object. The test initializes two programs of BPF_PROG_TYPE_XDP: progA acts as the entry point for bpf_prog_test_run_xdp() and its expected_attach_type can neither be of be BPF_XDP_DEVMAP nor BPF_XDP_CPUMAP. progA calls into a slot of a tailcall map it owns. progB's expected_attach_type must be BPF_XDP_DEVMAP to pass xdp_is_valid_access() validation. The program returns struct xdp_md's egress_ifindex, and the latter is only allowed to be accessed under mentioned expected_attach_type. progB is then inserted into the tailcall which progA calls. The underlying issue goes beyond XDP though. Another example are programs of type BPF_PROG_TYPE_CGROUP_SOCK_ADDR. sock_addr_is_valid_access() as well as sock_addr_func_proto() have different logic depending on the programs' expected_attach_type. Similarly, a program attached to BPF_CGROUP_INET4_GETPEERNAME should not be allowed doing a tailcall into a program which calls bpf_bind() out of BPF which is only enabled for BPF_CGROUP_INET4_CONNECT. In short, specifying expected_attach_type allows to open up additional functionality or restrictions beyond what the basic bpf_prog_type enables. The use of tailcalls must not violate these constraints. Fix it by enforcing expected_attach_type in __bpf_prog_map_compatible(). Note that we only enforce this for tailcall maps, but not for BPF devmaps or cpumaps: There, the programs are invoked through dev_map_bpf_prog_run*() and cpu_map_bpf_prog_run*() which set up a new environment / context and therefore these situations are not prone to this issue.
zetlyn/cve-nvd · 2025-11-12
cvss 7.8 product Linux status Deferred vendor Linux source