Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #91901 > unrolled thread

Bug#1132622: CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding

Started byBenjamin Leon Dubos <bleondubos@gmail.com>
First post2026-04-04 03:20 +0200
Last post2026-04-14 05:20 +0200
Articles 4 — 3 participants

Back to article view | Back to linux.debian.kernel


Contents

  Bug#1132622: CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding Benjamin Leon Dubos <bleondubos@gmail.com> - 2026-04-04 03:20 +0200
    Bug#1132622: CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding Salvatore Bonaccorso <carnil@debian.org> - 2026-04-04 08:00 +0200
    Bug#1132622: marked as done (CVE-2026-23417: fix BPF PROBE_MEM32  constant blinding) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2026-04-05 10:30 +0200
    Bug#1132622: marked as done (CVE-2026-23417: fix BPF PROBE_MEM32  constant blinding) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2026-04-14 05:20 +0200

#91901 — Bug#1132622: CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding

FromBenjamin Leon Dubos <bleondubos@gmail.com>
Date2026-04-04 03:20 +0200
SubjectBug#1132622: CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding
Message-ID<MFXQ5-cwd2-1@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Source: linux
Version: 6.19.10-1
Severity: grave
Tags: patch security
X-Debbugs-Cc: bleondubos@gmail.com, Debian Security Team <team@security.debian.org>

This is a backport for CVE-2026-23417 (BPF JIT Blinding bypass) 
targeting the linux package in Sid (6.19.10-1).

I have verified the patch by successfully compiling kernel/bpf/core.o 
in a Debian Sid environment. The patch follows DEP-3 standards and 
addresses the issue where BPF_ST | BPF_PROBE_MEM32 instructions 
were bypassing constant blinding.

The fix is based on the upstream commit by Linus Torvalds.
Attached is the DEP-3 formatted patch.


-- System Information:
Debian Release: forky/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)

Kernel: Linux 6.19.10+deb14-amd64 (SMP w/2 CPU threads; PREEMPT)
Locale: LANG=es_CL.UTF-8, LC_CTYPE=es_CL.UTF-8 (charmap=UTF-8), LANGUAGE=es_CL:es
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

[toc] | [next] | [standalone]


#91902

FromSalvatore Bonaccorso <carnil@debian.org>
Date2026-04-04 08:00 +0200
Message-ID<MG2d3-cz19-1@gated-at.bofh.it>
In reply to#91901
Hi,

On Fri, Apr 03, 2026 at 10:16:15PM -0300, Benjamin Leon Dubos wrote:
> Source: linux
> Version: 6.19.10-1
> Severity: grave
> Tags: patch security
> X-Debbugs-Cc: bleondubos@gmail.com, Debian Security Team <team@security.debian.org>
> 
> This is a backport for CVE-2026-23417 (BPF JIT Blinding bypass) 
> targeting the linux package in Sid (6.19.10-1).
> 
> I have verified the patch by successfully compiling kernel/bpf/core.o 
> in a Debian Sid environment. The patch follows DEP-3 standards and 
> addresses the issue where BPF_ST | BPF_PROBE_MEM32 instructions 
> were bypassing constant blinding.
> 
> The fix is based on the upstream commit by Linus Torvalds.
> Attached is the DEP-3 formatted patch.

Thanks for the patch (but it is not needed, as we follow stable
upstream series this is included in 6.19.11 which will be uploaded to
unstable).

I added a bug closer to the respective entry, but in general it's not
really needed to fill bugs for CVEs for the linux kernel, tracking of
the CVE is aleady almost well established.

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#91911 — Bug#1132622: marked as done (CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding)

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2026-04-05 10:30 +0200
SubjectBug#1132622: marked as done (CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding)
Message-ID<MGr1M-cPYu-17@gated-at.bofh.it>
In reply to#91901

[Multipart message — attachments visible in raw view] — view raw

Your message dated Sun, 05 Apr 2026 08:23:34 +0000
with message-id <E1w9Ila-0000000Cxw6-2UBN@fasolo.debian.org>
and subject line Bug#1132622: fixed in linux 6.19.11-1
has caused the Debian Bug report #1132622,
regarding CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
1132622: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1132622
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [next] | [standalone]


#92009 — Bug#1132622: marked as done (CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding)

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2026-04-14 05:20 +0200
SubjectBug#1132622: marked as done (CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding)
Message-ID<MJCtH-eYNE-1@gated-at.bofh.it>
In reply to#91901

[Multipart message — attachments visible in raw view] — view raw

Your message dated Tue, 14 Apr 2026 03:13:06 +0000
with message-id <E1wCUD4-0000000FFz6-1omF@fasolo.debian.org>
and subject line Bug#1132622: fixed in linux 7.0-1~exp1
has caused the Debian Bug report #1132622,
regarding CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
1132622: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1132622
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web