CVE-2026-68295
Last modified
CVE-2026-68295 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Zero-extend signed ALU32 div/mod results ALU32 operations write a 32-bit result and leave the upper 32 bits of the BPF register zero. The LoongArch JIT sign-extends the result of signed ALU32 BPF_DIV and BPF_MOD (off=1), so a negative 32-bit quotient or remainder leaves bits 63:32 set in JITted code while the verifier and interpreter model those bits as zero. Keep sign-extension on the operands, which signed divide needs, and zero-extend the ALU32 result after the divide or modulo instruction, matching the unsigned ALU32 div/mod paths and every other ALU32 operation in this JIT..
Description
In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Zero-extend signed ALU32 div/mod results ALU32 operations write a 32-bit result and leave the upper 32 bits of the BPF register zero. The LoongArch JIT sign-extends the result of signed ALU32 BPF_DIV and BPF_MOD (off=1), so a negative 32-bit quotient or remainder leaves bits 63:32 set in JITted code while the verifier and interpreter model those bits as zero. Keep sign-extension on the operands, which signed divide needs, and zero-extend the ALU32 result after the divide or modulo instruction, matching the unsigned ALU32 div/mod paths and every other ALU32 operation in this JIT.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 2425c9e002d2a1fdca34261b2fa6713eafef2163, < 716cb29dbed4d62e9e108950a1a82bcba4cc2d45; >= 2425c9e002d2a1fdca34261b2fa6713eafef2163, < dacd348b8a993373576fe2ee2d8b114740ba57a6 |
| Linux | Linux | 6.7 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68295?
How severe is CVE-2026-68295?
How do I fix CVE-2026-68295?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6829nesquena hermes-webui contains a trust-boundary failure vuln…6.3
- CVE-2026-68290In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68291In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68292In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68293In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68294In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68296In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68297In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68298In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68299In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6830nesquena hermes-webui contains an environment variable leaka…4.8
- CVE-2026-68300In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-68295?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
