Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1288392
| From | Benjamin Leon Dubos <bleondubos@gmail.com> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.kernel |
| Subject | Bug#1132622: CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding |
| Date | 2026-04-04 03:20 +0200 |
| Message-ID | <MFXQ5-cwd2-1@gated-at.bofh.it> (permalink) |
| Organization | linux.* mail to news gateway |
Cross-posted to 2 groups.
[Multipart message — attachments visible in raw view] - view raw
Source: linux Version: 6.19.10-1 Severity: grave Tags: patch security X-Debbugs-Cc: bleondubos@gmail.com, Debian Security Team <team@security.debian.org> This is a backport for CVE-2026-23417 (BPF JIT Blinding bypass) targeting the linux package in Sid (6.19.10-1). I have verified the patch by successfully compiling kernel/bpf/core.o in a Debian Sid environment. The patch follows DEP-3 standards and addresses the issue where BPF_ST | BPF_PROBE_MEM32 instructions were bypassing constant blinding. The fix is based on the upstream commit by Linus Torvalds. Attached is the DEP-3 formatted patch. -- System Information: Debian Release: forky/sid APT prefers unstable APT policy: (500, 'unstable') Architecture: amd64 (x86_64) Kernel: Linux 6.19.10+deb14-amd64 (SMP w/2 CPU threads; PREEMPT) Locale: LANG=es_CL.UTF-8, LC_CTYPE=es_CL.UTF-8 (charmap=UTF-8), LANGUAGE=es_CL:es Shell: /bin/sh linked to /usr/bin/dash Init: systemd (via /run/systemd/system) LSM: AppArmor: enabled
Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread
Bug#1132622: CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding Benjamin Leon Dubos <bleondubos@gmail.com> - 2026-04-04 03:20 +0200 Bug#1132622: CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding Salvatore Bonaccorso <carnil@debian.org> - 2026-04-04 08:00 +0200
csiph-web