CVE-2026-72428
Last modified
CVE-2026-72428 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stack slot index in nospec checks check_stack_write_fixed_off() computes the byte slot for a fixed-offset stack write as -off - 1, and records each written byte in slot_type[] with (slot - i) % BPF_REG_SIZE. The Spectre v4 sanitization pre-check uses slot_type[i] instead. For a 4-byte write at fp-8 after the lower half of fp-8 has been zeroed, the pre-check scans bytes 0..3 and sees STACK_ZERO while the actual write updates bytes 7..4. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stack slot index in nospec checks check_stack_write_fixed_off() computes the byte slot for a fixed-offset stack write as -off - 1, and records each written byte in slot_type[] with (slot - i) % BPF_REG_SIZE. The Spectre v4 sanitization pre-check uses slot_type[i] instead. For a 4-byte write at fp-8 after the lower half of fp-8 has been zeroed, the pre-check scans bytes 0..3 and sees STACK_ZERO while the actual write updates bytes 7..4. That can leave the second half-slot write without nospec_result even though the bytes being overwritten still require sanitization. Use the same slot index in the sanitization pre-check that the write path uses when updating slot_type[].
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 0e9280654aa482088ee6ef3deadef331f5ac5fb0, < e62268e695075a481a6c4feeb022c19cf57422a6; >= 2039f26f3aca5b0e419b98f65dd36481337b86ee, < a71eb8f730a91271cf47ce291e785b6b7e54622f; >= 2039f26f3aca5b0e419b98f65dd36481337b86ee, < ca119656baa8f48a56e0c2f3ab63fdd33ca9e307; >= 2039f26f3aca5b0e419b98f65dd36481337b86ee, < 475405593de2b796224c6297aece44f321195919; >= 2039f26f3aca5b0e419b98f65dd36481337b86ee, < f1471aa76d74e0df3b2a90731ca0208f498c670b; >= 2039f26f3aca5b0e419b98f65dd36481337b86ee, < 68b41e68a62299f26cb16af422b5c7d1c69dafd9; >= 2039f26f3aca5b0e419b98f65dd36481337b86ee, < db8f1dcf5950b91886b9df4270bc816370d292c1; >= 2039f26f3aca5b0e419b98f65dd36481337b86ee, < d1d53aa30ab3b5ae89161c9cc840b3f7489ad386; 872968502114d68c21419cf7eb5ab97717e7b803; f5893af2704eb763eb982f01d573f5b19f06b623; 0b27bdf02c400684225ee5ee99970bcbf5082282; >= 5.10.56, < 5.10.261; >= 4.19.207, < 4.20; >= 5.4.146, < 5.5; >= 5.13.8, < 5.14 |
| Linux | Linux | 5.14 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-72428?
How severe is CVE-2026-72428?
How do I fix CVE-2026-72428?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72422In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-72423In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-72424In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72425In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-72426In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-72427In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72429In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-7243A vulnerability was identified in Totolink A8000RU 7.1cu.643…9.8
- CVE-2026-72430In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72431In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72432In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72433In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-72428?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
