← All Advisories

CVE-2026-72402

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-72402

Key Details

CVECVE-2026-72402
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

bpf: Mask pseudo pointer values in verifier logs

print_bpf_insn() masks ldimm64 immediates for pointer-bearing pseudo

sources when pointer leaks are not allowed, but the mask only covers

BPF_PSEUDO_MAP_FD and BPF_PSEUDO_MAP_VALUE.

BPF_PSEUDO_MAP_IDX, BPF_PSEUDO_MAP_IDX_VALUE, and BPF_PSEUDO_BTF_ID can

also be resolved to kernel pointer values before the verifier log prints

the instruction. Include them in the existing pointer classification so

the log prints 0x0 instead of the rewritten address. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-72402
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-72402