In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix kernel stack corruption in tailcall with CFI When… (CVE-2026-92518)
A high-severity vulnerability in the Linux kernel affecting the riscv architecture and BPF subsystem was resolved. The issue involved kernel stack corruption caused by incorrect handling of the tailcall jump offset when CONFIG_CFI_CLANG is enabled. This flaw could lead to skipping stack pointer adjustments, resulting in kernel stack corruption.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-92518) in the Linux kernel's riscv BPF implementation occurs when CONFIG_CFI_CLANG is enabled. The program's bpf_func skips the kcfi instruction during setup, but including it again in the tailcall jump offset causes the jump to skip an extra 4 bytes. This skips the stack pointer adjustment, leading to kernel stack corruption. This flaw has been resolved in the Linux kernel.
Potential Impact
Successful exploitation of this vulnerability could cause kernel stack corruption, potentially leading to system instability, crashes, or privilege escalation due to corrupted kernel state. The CVSS score of 7.8 indicates high severity with high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel. Users should apply the official kernel updates that include this fix. Since this is not a cloud service, remediation depends on applying the updated kernel version. Patch status is not explicitly stated in the input; check the vendor advisory for the exact fixed kernel versions and update accordingly.
In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix kernel stack corruption in tailcall with CFI When… (CVE-2026-92518)
Description
A high-severity vulnerability in the Linux kernel affecting the riscv architecture and BPF subsystem was resolved. The issue involved kernel stack corruption caused by incorrect handling of the tailcall jump offset when CONFIG_CFI_CLANG is enabled. This flaw could lead to skipping stack pointer adjustments, resulting in kernel stack corruption.
CVSS v3.1
Score 7.8high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-92518) in the Linux kernel's riscv BPF implementation occurs when CONFIG_CFI_CLANG is enabled. The program's bpf_func skips the kcfi instruction during setup, but including it again in the tailcall jump offset causes the jump to skip an extra 4 bytes. This skips the stack pointer adjustment, leading to kernel stack corruption. This flaw has been resolved in the Linux kernel.
Potential Impact
Successful exploitation of this vulnerability could cause kernel stack corruption, potentially leading to system instability, crashes, or privilege escalation due to corrupted kernel state. The CVSS score of 7.8 indicates high severity with high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel. Users should apply the official kernel updates that include this fix. Since this is not a cloud service, remediation depends on applying the updated kernel version. Patch status is not explicitly stated in the input; check the vendor advisory for the exact fixed kernel versions and update accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-63c9-g3g8-7rpv
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-92518"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6aade51955bf5e2cf5edc042
Added to database: 09/19/2026, 01:27:53 UTC
Last enriched: 09/19/2026, 01:44:41 UTC
Last updated: 09/19/2026, 05:01:37 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.