---
id: CVE-2026-93174
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: Copy per-CPU map value padding in copy_map_value_long()

  In kernel, per-CPU map elements are stored with
  round_up(map->value_size, 8) bytes
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: Copy per-CPU map value padding in copy_map_value_long()

  In kernel, per-CPU map elements are stored with
  round_up(map->value_size, 8) bytes. On UAPI lookup paths, …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 448325199f574d33824dbf9121efb03558412966 <
    953e85da53541a8dc3e7ad4e8532f29a34a32eae
  - >-
    Linux >= 448325199f574d33824dbf9121efb03558412966 <
    003bf840ed3326bd01396ce7d5b431cef0d371e7
  - >-
    Linux >= 448325199f574d33824dbf9121efb03558412966 <
    5e9f69829835521aa2942d1d14bd0990fbc6991e
  - >-
    Linux >= 448325199f574d33824dbf9121efb03558412966 <
    ff3f22ed8d2f350b4c24ee26e33daea5f08d58ef
  - >-
    Linux >= 448325199f574d33824dbf9121efb03558412966 <
    7cf9cd98cf6f0df3befc167ca6b54c07014d71de
  - Linux 6.1
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:18:13.167'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93174'
references:
  - url: 'https://git.kernel.org/stable/c/003bf840ed3326bd01396ce7d5b431cef0d371e7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5e9f69829835521aa2942d1d14bd0990fbc6991e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7cf9cd98cf6f0df3befc167ca6b54c07014d71de'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/953e85da53541a8dc3e7ad4e8532f29a34a32eae'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ff3f22ed8d2f350b4c24ee26e33daea5f08d58ef'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.730Z'
epss: 0.00209
epssPercentile: 0.09793
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

bpf: Copy per-CPU map value padding in copy_map_value_long()

In kernel, per-CPU map elements are stored with
round_up(map->value_size, 8) bytes. On UAPI lookup paths, it copies the
rounded size for each CPU into a temporary buffer.

However, copy_map_value_long() passes 'map->value_size' to
bpf_obj_memcpy(). When the map has special fields, bpf_obj_memcpy() copies
around those fields with memcpy(), and does not copy the tail padding
between 'map->value_size' and round_up(map->value_size, 8).

The temporary UAPI lookup buffers are allocated without __GFP_ZERO. As a
result, when the per-CPU map's value size is not equal to
round_up(map->value_size, 8), UAPI LOOKUP_ELEM and its variants can return
stale heap contents from that padding to user space. The same issue
applies to bpf_iter for per-CPU maps.

Pass round_up(map->value_size, 8) to bpf_obj_memcpy() from
copy_map_value_long(), so per-CPU maps both with and without special
fields copy the entire per-CPU slot. Remove the now redundant round_up()
from bpf_obj_memcpy()'s long_memcpy path.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
