---
id: CVE-2026-93270
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: Disallow interpreter fallback for BPF_ADDR_PERCPU insn

  The BPF_MOV64_PERCPU_REG insn requires JIT to emit native code to for
  'dst_reg = src_reg + <percpu_base_off…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bpf: Disallow interpreter fallback for BPF_ADDR_PERCPU insn

  The BPF_MOV64_PERCPU_REG insn requires JIT to emit native code to for
  'dst_reg = src_reg + <percpu_base_off…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 7bdbf7446305cb65c510c16d57cde82bc76b234a <
    57cf929a33cb76be3f24886073ae820b4c496914
  - >-
    Linux >= 7bdbf7446305cb65c510c16d57cde82bc76b234a <
    7a0855e73757ee9cf25ba635a1c735018ecba742
  - Linux 6.10
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T16:17:24.020'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93270'
references:
  - url: 'https://git.kernel.org/stable/c/57cf929a33cb76be3f24886073ae820b4c496914'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7a0855e73757ee9cf25ba635a1c735018ecba742'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-24T16:47:15.838Z'
epss: 0.00176
epssPercentile: 0.06431
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

bpf: Disallow interpreter fallback for BPF_ADDR_PERCPU insn

The BPF_MOV64_PERCPU_REG insn requires JIT to emit native code to for
'dst_reg = src_reg + <percpu_base_off>'.

However, the interpreter ignores the 'off' at its ALU64_MOV_X label.
The 'off' indicates the insn is BPF_MOV64_PERCPU_REG insn. Then, when
the interpreter loads memory from the register, it will hit a page
fault.

[    2.545572] BUG: unable to handle page fault for address: ffffffffacaaf034
[    2.546485] #PF: supervisor read access in kernel mode
[    2.547167] #PF: error_code(0x0000) - not-present page
[    2.547850] PGD 134e63067 P4D 134e63067 PUD 134e64063 PMD 10021c063 PTE 800ffffeca550062
[    2.548912] Oops: Oops: 0000 [#1] SMP PTI

Set jit_required as true in order to disallow interpreter fallback in
core.c::__bpf_prog_select_runtime(), if any BPF_ADDR_PERCPU insn is
patched to the prog.

BTW, rename the helper bpf_map_supports_cpu_flags() to
bpf_map_is_percpu_map().

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
