A flaw in the Linux kernel's BPF disassembler was reported after syzbot and UBSAN identified an out-of-bounds array access in print_bpf_insn(), the function used to format BPF instructions for verifier diagnostics. The bug is triggered when a malformed signed-load instruction using BPF_MEMSX | BPF_DW reaches diagnostic disassembly code before opcode validation fully rejects it, causing the kernel to index past the end of the three-entry bpf_ldsx_string[] table. No evidence has been presented that the issue enables privilege escalation, information disclosure, remote exploitation, or abuse by unprivileged users.
A two-patch fix was proposed and then applied to bpf/bpf.git, changing the disassembler to reject invalid signed double-word load encodings and fall back to the existing BUG_ldx diagnostic path instead of performing the unsafe table lookup. The patch series, authored by Kumar Kartikeya Dwivedi, reviewed by Jiayuan Chen, and merged by Daniel Borkmann, also adds a self-test to catch regressions. The issue appears to exist in current kernel source, but affected released versions and downstream distributions have not yet been identified.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The two-patch series was applied to bpf/bpf.git master by Daniel Borkmann, including the disassembler fix and a regression selftest. Patchwork-bot announced the applied commits as 37e5c4f4d285 for the fix and 175a58668e2d for the selftest.
Kumar Kartikeya Dwivedi submitted a two-patch bpf-next series to treat signed double-word loads as invalid in print_bpf_insn() and add a selftest for the malformed instruction. The fix prevents the disassembler from indexing past bpf_ldsx_string[] and instead falls back to the existing invalid-instruction diagnostic path.
syzbot reported an out-of-bounds array access in the Linux kernel function print_bpf_insn(), triggered by a malformed BPF_MEMSX | BPF_DW instruction reaching diagnostic disassembly code. The issue was reproduced with UBSAN, which detected an array index past the end of the signed-load mnemonic table.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
linuxsecurity.com
Open sourcelore.kernel.org
Open sourcesyzkaller.appspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.