{"id":"CVE-2026-53078","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix same-register dst/src OOB read and pointer leak in sock_ops\n\nWhen a BPF sock_ops program accesses ctx fields with dst_reg == src_reg,\nthe SOCK_OPS_GET_SK() and…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix same-register dst/src OOB read and pointer leak in sock_ops\n\nWhen a BPF sock_ops program accesses ctx fields with dst_reg == src_reg,\nthe SOCK_OPS_GET_SK() and…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-125"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 5.4.61, < 5.5","linux_kernel >= 5.7.18, < 5.8","linux_kernel >= 5.8.4, < 5.9","linux_kernel >= 5.9.1, < 7.0.10","linux_kernel = 5.9"],"patched":["linux_kernel 7.0.10"],"published":"2026-06-24","updated":"2026-09-14","sourceUpdated":"2026-09-14T12:17:43.033","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-53078","references":[{"url":"https://git.kernel.org/stable/c/0e6b30657bbc771f38025c828d722b6162428508","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/10f86a2a5c91fc4c4d001960f1c21abe52545ef6","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/18e3ffde1822f0b48b1753bf34aa97ce839df1d8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/22400725de070b787cd6d806c5795370ab46d269","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a2c98141e0a75f2d4a7d78b0316c88b3da784ac","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4c1c5efd9d1d74743d41ce4e1600501b4feb6827","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/64eaf4ecda007140ddcdb28e00c48c9c69aaba39","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/db1200ec2c3ddf119d4d9ba67982063df06bbacb","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53078.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-53078"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492299"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-53078"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53078"},{"url":"https://lore.kernel.org/linux-cve-announce/2026062406-CVE-2026-53078-bc4a@gregkh/T"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00176,"epssPercentile":0.0636,"ingestedAt":"2026-08-03T10:24:20.108Z","scores":{"nvd":7.8,"vendor":6.4},"slug":"CVE-2026-53078","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix same-register dst/src OOB read and pointer leak in sock_ops\n\nWhen a BPF sock_ops program accesses ctx fields with dst_reg == src_reg,\nthe SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros fail to zero the\ndestination register in the !fullsock / !locked_tcp_sock path.\n\nBoth macros borrow a temporary register to check is_fullsock /\nis_locked_tcp_sock when dst_reg == src_reg, because dst_reg holds the\nctx pointer. When the check is false (e.g., TCP_NEW_SYN_RECV state with\na request_sock), dst_reg should be zeroed but is not, leaving the stale\nctx pointer:\n\n - SOCK_OPS_GET_SK: dst_reg retains the ctx pointer, passes NULL checks\n   as PTR_TO_SOCKET_OR_NULL, and can be used as a bogus socket pointer,\n   leading to stack-out-of-bounds access in helpers like\n   bpf_skc_to_tcp6_sock().\n\n - SOCK_OPS_GET_FIELD: dst_reg retains the ctx pointer which the\n   verifier believes is a SCALAR_VALUE, leaking a kernel pointer.\n\nFix both macros by:\n - Changing JMP_A(1) to JMP_A(2) in the fullsock path to skip the\n   added instruction.\n - Adding BPF_MOV64_IMM(si->dst_reg, 0) after the temp register\n   restore in the !fullsock path, placed after the restore because\n   dst_reg == src_reg means we need src_reg intact to read ctx->temp.\n\n## Affected\n\n- `linux_kernel >= 5.4.61, < 5.5`\n- `linux_kernel >= 5.7.18, < 5.8`\n- `linux_kernel >= 5.8.4, < 5.9`\n- `linux_kernel >= 5.9.1, < 7.0.10`\n- `linux_kernel = 5.9`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 7.0.10`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53078.json)","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}