Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1288401
| From | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.kernel |
| Subject | Bug#1132622: CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding |
| Date | 2026-04-04 08:00 +0200 |
| Message-ID | <MG2d3-cz19-1@gated-at.bofh.it> (permalink) |
| References | <MFXQ5-cwd2-1@gated-at.bofh.it> <MFXQ5-cwd2-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Cross-posted to 2 groups.
Hi, On Fri, Apr 03, 2026 at 10:16:15PM -0300, Benjamin Leon Dubos wrote: > Source: linux > Version: 6.19.10-1 > Severity: grave > Tags: patch security > X-Debbugs-Cc: bleondubos@gmail.com, Debian Security Team <team@security.debian.org> > > This is a backport for CVE-2026-23417 (BPF JIT Blinding bypass) > targeting the linux package in Sid (6.19.10-1). > > I have verified the patch by successfully compiling kernel/bpf/core.o > in a Debian Sid environment. The patch follows DEP-3 standards and > addresses the issue where BPF_ST | BPF_PROBE_MEM32 instructions > were bypassing constant blinding. > > The fix is based on the upstream commit by Linus Torvalds. > Attached is the DEP-3 formatted patch. Thanks for the patch (but it is not needed, as we follow stable upstream series this is included in 6.19.11 which will be uploaded to unstable). I added a bug closer to the respective entry, but in general it's not really needed to fill bugs for CVEs for the linux kernel, tracking of the CVE is aleady almost well established. Regards, Salvatore
Back to linux.debian.bugs.dist | Previous | Next — Previous in thread | Find similar | Unroll thread
Bug#1132622: CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding Benjamin Leon Dubos <bleondubos@gmail.com> - 2026-04-04 03:20 +0200 Bug#1132622: CVE-2026-23417: fix BPF PROBE_MEM32 constant blinding Salvatore Bonaccorso <carnil@debian.org> - 2026-04-04 08:00 +0200
csiph-web