---
id: CVE-2026-53078
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops

  When a BPF sock_ops program accesses ctx fields with dst_reg == src_reg,
  the SOCK_OPS_GET_SK() and…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops

  When a BPF sock_ops program accesses ctx fields with dst_reg == src_reg,
  the SOCK_OPS_GET_SK() and…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-125
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 5.4.61, < 5.5'
  - 'linux_kernel >= 5.7.18, < 5.8'
  - 'linux_kernel >= 5.8.4, < 5.9'
  - 'linux_kernel >= 5.9.1, < 7.0.10'
  - linux_kernel = 5.9
patched:
  - linux_kernel 7.0.10
published: '2026-06-24'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T12:17:43.033'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53078'
references:
  - url: 'https://git.kernel.org/stable/c/0e6b30657bbc771f38025c828d722b6162428508'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/10f86a2a5c91fc4c4d001960f1c21abe52545ef6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/18e3ffde1822f0b48b1753bf34aa97ce839df1d8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/22400725de070b787cd6d806c5795370ab46d269'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2a2c98141e0a75f2d4a7d78b0316c88b3da784ac'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4c1c5efd9d1d74743d41ce4e1600501b4feb6827'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/64eaf4ecda007140ddcdb28e00c48c9c69aaba39'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/db1200ec2c3ddf119d4d9ba67982063df06bbacb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53078.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-53078'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2492299'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-53078'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53078'
  - url: >-
      https://lore.kernel.org/linux-cve-announce/2026062406-CVE-2026-53078-bc4a@gregkh/T
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00176
epssPercentile: 0.06363
ingestedAt: '2026-08-03T10:24:20.108Z'
scores:
  nvd: 7.8
  vendor: 6.4
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops

When a BPF sock_ops program accesses ctx fields with dst_reg == src_reg,
the SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros fail to zero the
destination register in the !fullsock / !locked_tcp_sock path.

Both macros borrow a temporary register to check is_fullsock /
is_locked_tcp_sock when dst_reg == src_reg, because dst_reg holds the
ctx pointer. When the check is false (e.g., TCP_NEW_SYN_RECV state with
a request_sock), dst_reg should be zeroed but is not, leaving the stale
ctx pointer:

 - SOCK_OPS_GET_SK: dst_reg retains the ctx pointer, passes NULL checks
   as PTR_TO_SOCKET_OR_NULL, and can be used as a bogus socket pointer,
   leading to stack-out-of-bounds access in helpers like
   bpf_skc_to_tcp6_sock().

 - SOCK_OPS_GET_FIELD: dst_reg retains the ctx pointer which the
   verifier believes is a SCALAR_VALUE, leaking a kernel pointer.

Fix both macros by:
 - Changing JMP_A(1) to JMP_A(2) in the fullsock path to skip the
   added instruction.
 - Adding BPF_MOV64_IMM(si->dst_reg, 0) after the temp register
   restore in the !fullsock path, placed after the restore because
   dst_reg == src_reg means we need src_reg intact to read ctx->temp.

## Affected

- `linux_kernel >= 5.4.61, < 5.5`
- `linux_kernel >= 5.7.18, < 5.8`
- `linux_kernel >= 5.8.4, < 5.9`
- `linux_kernel >= 5.9.1, < 7.0.10`
- `linux_kernel = 5.9`

## Remediation

Upgrade past the affected range:

- `linux_kernel 7.0.10`

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53078.json)
