{"id":"CVE-2026-92517","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, riscv: Fix extable handling for arena load_acquire\n\nemit_atomic_ld_st() returns 1 to have build_body() skip the zext after\na sub-word load_acquire","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, riscv: Fix extable handling for arena load_acquire\n\nemit_atomic_ld_st() returns 1 to have build_body() skip the zext after\na sub-word load_acquire. The caller does…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= fb7cefabae8117c203155ef169a386bec43bbba9 < 26d9496c826586338d1b8c27edfec4a19a89f462","Linux >= fb7cefabae8117c203155ef169a386bec43bbba9 < 08fe2eaa609180c1baeb76c2629a9c82263b0427","Linux >= fb7cefabae8117c203155ef169a386bec43bbba9 < 5eb8921371c6fd117d4a328b6053dfda38707df8","Linux 6.18"],"published":"2026-09-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:17:54.587","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92517","references":[{"url":"https://git.kernel.org/stable/c/08fe2eaa609180c1baeb76c2629a9c82263b0427","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/26d9496c826586338d1b8c27edfec4a19a89f462","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5eb8921371c6fd117d4a328b6053dfda38707df8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-17T16:21:47.778Z","epss":0.00198,"epssPercentile":0.09826,"slug":"CVE-2026-92517","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nbpf, riscv: Fix extable handling for arena load_acquire\n\nemit_atomic_ld_st() returns 1 to have build_body() skip the zext after\na sub-word load_acquire. The caller does \"ret = ret ?:\nadd_exception_handler(...)\", which skips add_exception_handler() on any\nnon-zero ret, so the extable entry is missing and a faulting\nPROBE_ATOMIC load_acquire oopses.\n\nREG_DONT_CLEAR_MARKER leaves rd stale on fault, and the verifier still\nthinks the load overwrote it, so a program can leak it through a map.\n\nCheck ret >= 0 before calling add_exception_handler(), and pass rd for\nLOAD_ACQ so the fault zeroes rd like a PROBE_MEM load. Return ret\nunchanged for the zext skip.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}