---
id: CVE-2026-43010
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: Reject sleepable kprobe_multi programs at attach time

  kprobe.multi programs run in atomic/RCU context and cannot sleep.
  However, bpf_kprobe_multi_link_attach() di…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: Reject sleepable kprobe_multi programs at attach time

  kprobe.multi programs run in atomic/RCU context and cannot sleep.
  However, bpf_kprobe_multi_link_attach() di…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 5.18, < 6.18.22'
  - 'linux_kernel >= 6.19, < 6.19.12'
  - linux_kernel = 7.0
patched:
  - linux_kernel 6.19.12
published: '2026-05-01'
updated: '2026-07-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-43010'
references:
  - url: 'https://git.kernel.org/stable/c/89327ed787746a7aa4db3c97f91d2e294228932b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d97b19fe5265f7901b2c862f88a4eb1b129a0b61'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/dc9a060d76c12b23c5f378ee115d5e5d03d8bbf3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/eb7024bfcc5f68ed11ed9dd4891a3073c15f04a8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f952157e695fd434bdc05af63a703bb082a78717'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00162
epssPercentile: 0.04609
ingestedAt: '2026-07-04T12:56:09.371Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject sleepable kprobe_multi programs at attach time

kprobe.multi programs run in atomic/RCU context and cannot sleep.
However, bpf_kprobe_multi_link_attach() did not validate whether the
program being attached had the sleepable flag set, allowing sleepable
helpers such as bpf_copy_from_user() to be invoked from a non-sleepable
context.

This causes a "sleeping function called from invalid context" splat:

  BUG: sleeping function called from invalid context at ./include/linux/uaccess.h:169
  in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 1787, name: sudo
  preempt_count: 1, expected: 0
  RCU nest depth: 2, expected: 0

Fix this by rejecting sleepable programs early in
bpf_kprobe_multi_link_attach(), before any further processing.

## Affected

- `linux_kernel >= 5.18, < 6.18.22`
- `linux_kernel >= 6.19, < 6.19.12`
- `linux_kernel = 7.0`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.19.12`
