Answer in brief
CVE-2026-92517 records a Unknown severity vulnerability in bpf, riscv: Fix extable handling for arena load_acquire. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=fb7cefabae8117c203155ef169a386bec43bbba9 <26d9496c826586338d1b8c27edfec4a19a89f462 || >=fb7cefabae8117c203155ef169a386bec43bbba9 <08fe2eaa609180c1baeb76c2629a9c82263b0427 || >=fb7cefabae8117c203155ef169a386bec43bbba9 <5eb8921371c6fd117d4a328b6053dfda38707df8 | 26d9496c826586338d1b8c27edfec4a19a89f462, 08fe2eaa609180c1baeb76c2629a9c82263b0427, 5eb8921371c6fd117d4a328b6053dfda38707df8 |
| Linux/Linuxgeneric | 6.18 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf, riscv: Fix extable handling for arena load_acquire emit_atomic_ld_st() returns 1 to have build_body() skip the zext after a sub-word load_acquire. The caller does "ret = ret ?: add_exception_handler(...)", which skips add_exception_handler() on any non-zero ret, so the extable entry is missing and a faulting PROBE_ATOMIC load_acquire oopses. REG_DONT_CLEAR_MARKER leaves rd stale on fault, and the verifier still thinks the load overwrote it, so a program can leak it through a map. Check ret >= 0 before calling add_exception_handler(), and pass rd for LOAD_ACQ so the fault zeroes rd like a PROBE_MEM load. Return ret unchanged for the zext skip.
Quoted source text, attributed separately from HOL analysis.