In the Linux kernel, the following vulnerability has been resolved: bpf: Reject arena frees below the arena base bpf_arena_free_pages() accepts… (CVE-2026-93045)
A high-severity vulnerability in the Linux kernel's BPF subsystem was resolved. The issue involves improper handling of arena frees in bpf_arena_free_pages(), where scalar arena addresses below the arena base could lead to out-of-range free-tree offsets. This flaw could allow allocations to return addresses below the arena mapping, potentially leading to serious memory corruption. The vulnerability is tracked as CVE-2026-93045 and has a CVSS score of 7.8.
AI Analysis
Technical Summary
The vulnerability in the Linux kernel's BPF subsystem arises because bpf_arena_free_pages() accepts scalar arena addresses and reconstructs full user addresses by masking to low 32 bits and adding the arena base. If the scalar value is below the low 32 bits of the arena base, the reconstructed full user address falls below user_vm_start. The existing clipping logic then produces an out-of-range free-tree offset. Subsequent allocations can reuse this offset, returning addresses below the arena mapping, which can cause memory corruption. The fix involves rejecting such frees before computing the clipped range.
Potential Impact
This vulnerability can lead to memory corruption by allowing allocations to return addresses outside the intended arena mapping. This can compromise confidentiality, integrity, and availability of the system, as indicated by the CVSS vector (Confidentiality: High, Integrity: High, Availability: High).
Mitigation Recommendations
No explicit patch or remediation details are provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject arena frees below the arena base bpf_arena_free_pages() accepts… (CVE-2026-93045)
Description
A high-severity vulnerability in the Linux kernel's BPF subsystem was resolved. The issue involves improper handling of arena frees in bpf_arena_free_pages(), where scalar arena addresses below the arena base could lead to out-of-range free-tree offsets. This flaw could allow allocations to return addresses below the arena mapping, potentially leading to serious memory corruption. The vulnerability is tracked as CVE-2026-93045 and has a CVSS score of 7.8.
CVSS v3.1
Score 7.8high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel's BPF subsystem arises because bpf_arena_free_pages() accepts scalar arena addresses and reconstructs full user addresses by masking to low 32 bits and adding the arena base. If the scalar value is below the low 32 bits of the arena base, the reconstructed full user address falls below user_vm_start. The existing clipping logic then produces an out-of-range free-tree offset. Subsequent allocations can reuse this offset, returning addresses below the arena mapping, which can cause memory corruption. The fix involves rejecting such frees before computing the clipped range.
Potential Impact
This vulnerability can lead to memory corruption by allowing allocations to return addresses outside the intended arena mapping. This can compromise confidentiality, integrity, and availability of the system, as indicated by the CVSS vector (Confidentiality: High, Integrity: High, Availability: High).
Mitigation Recommendations
No explicit patch or remediation details are provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-qfvw-mjm8-22x7
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-93045"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6aade51955bf5e2cf5edc03b
Added to database: 09/19/2026, 01:27:53 UTC
Last enriched: 09/19/2026, 01:44:07 UTC
Last updated: 09/19/2026, 03:00:23 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.