Kestrel
대시보드로 돌아가기
CVE-2026-98151UNKNOWNMITRENVD대응게시일: 2026. 09. 25.수정일: 2026. 09. 25.CNA: 416baaa9-dc9f-4396-8d5f-8c081fb06d67Received

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic Ta

위협 신호 · CVSS · EPSS · KEV

정기 패치· 높은 악용 신호 없음
CVSS
—unknown

이론적 심각도 점수

EPSS
—

예측 데이터 없음

KEV
미등재

실측 악용 기록 없음

권장 대응 기한60일 이내CISA SSVC 기준

계획된 패치 주기 내 조치(60일 이내)

외부 노출· KEV 미등재 · 자동화 어려움 · 부분 영향 · 외부 노출

CVSS 벡터 · 메트릭

CVSS 벡터 정보 없음

상세 설명

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic

Take the following unprivileged program as an example:

text
1r0 = bpf_map_lookup_elem(...) /* PTR_TO_MAP_VALUE, offset 0 */
2...
314: r0 += r1 /* r1 is a bounded scalar */
415: r9 = r0

Loading it triggers a verifier warning from reg_bounds_sanity_check():

text
1verifier bug: REG INVARIANTS VIOLATION (alu): const subreg tnum out
2of sync with range bounds r64={.base=0x0, .size=0x0}
3r32={.base=0x0, .size=0xffffffff} var_off=(0x0, 0x0)

What happens:

  1. Processing insn 14 (r0 += r1) in adjust_ptr_min_max_vals(), the new
    offset is computed into dst_reg's var_off and 32/64-bit ranges.

  2. Because pointer registers do not track 32-bit subregister bounds,
    __mark_reg32_unbounded() first sets r32 to the full range; r32 is
    re-derived from the offset at the end of the function by
    reg_bounds_sync().

  3. On the unprivileged path, sanitize_ptr_alu() is called and, via
    sanitize_speculative_path() -> push_stack(), snapshots the current
    register state and schedules the next instruction (insn 15) to be
    verified directly as a speculative path.

  4. That snapshot is taken between step 2 and the final reg_bounds_sync():
    at this point dst_reg's var_off still holds the (const) original
    offset while r32 has just been blanked to the full range, i.e. the two
    are out of sync. When the speculative path later verifies insn 15
    (r9 = r0), the inconsistent state reaches reg_bounds_sanity_check() and
    trips the warning.

var_off and the 32-bit range must always be consistent. There are two
ways to keep the snapshot consistent:

  1. sync var_off and r32 before the snapshot so they match, or
  2. leave r32 at its original (already consistent) value and blank it
    only after the snapshot.

The whole point of sanitize_ptr_alu() is to insert a harmless masking
sequence that keeps the access in bounds under speculation, so the state
it snapshots should faithfully represent that. Take approach 2: move
__mark_reg32_unbounded() to after sanitize_ptr_alu(), so the speculative
snapshot keeps the pointer's original, consistent r32. The non-speculative
path is unchanged: r32 is still blanked before the offset is applied and
re-derived by reg_bounds_sync().

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.