{"id":"CVE-2026-72402","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Mask pseudo pointer values in verifier logs\n\nprint_bpf_insn() masks ldimm64 immediates for pointer-bearing pseudo\nsources when pointer leaks are not allowed, but t…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Mask pseudo pointer values in verifier logs\n\nprint_bpf_insn() masks ldimm64 immediates for pointer-bearing pseudo\nsources when pointer leaks are not allowed, but t…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 4976b718c3551faba2c0616ef55ebeb74db1c5ca < c727b3d50ecb0f4992a964360771040a84026914","Linux >= 4976b718c3551faba2c0616ef55ebeb74db1c5ca < b96cb1235fcaa687291b1e1d910f0930d1939919","Linux >= 4976b718c3551faba2c0616ef55ebeb74db1c5ca < 1c53d16b174dd9e02243fc0e85089e2aa6a0d21a","Linux >= 4976b718c3551faba2c0616ef55ebeb74db1c5ca < 72a85e9464a5332fb2cd7efd26d9295275ceda2d","Linux 5.10"],"published":"2026-08-15","updated":"2026-09-21","sourceUpdated":"2026-09-21T14:17:17.413","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72402","references":[{"url":"https://git.kernel.org/stable/c/1c53d16b174dd9e02243fc0e85089e2aa6a0d21a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/72a85e9464a5332fb2cd7efd26d9295275ceda2d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b96cb1235fcaa687291b1e1d910f0930d1939919","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c727b3d50ecb0f4992a964360771040a84026914","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"epss":0.002,"epssPercentile":0.10166,"ingestedAt":"2026-09-21T13:37:22.842Z","slug":"CVE-2026-72402","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Mask pseudo pointer values in verifier logs\n\nprint_bpf_insn() masks ldimm64 immediates for pointer-bearing pseudo\nsources when pointer leaks are not allowed, but the mask only covers\nBPF_PSEUDO_MAP_FD and BPF_PSEUDO_MAP_VALUE.\n\nBPF_PSEUDO_MAP_IDX, BPF_PSEUDO_MAP_IDX_VALUE, and BPF_PSEUDO_BTF_ID can\nalso be resolved to kernel pointer values before the verifier log prints\nthe instruction. Include them in the existing pointer classification so\nthe log prints 0x0 instead of the rewritten address.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}