CVE-2026-68295 PUBLISHED

LoongArch: BPF: Zero-extend signed ALU32 div/mod results

Assigner: Linux
Reserved: 30.07.2026 Published: 10.08.2026 Updated: 10.08.2026

In the Linux kernel, the following vulnerability has been resolved:

LoongArch: BPF: Zero-extend signed ALU32 div/mod results

ALU32 operations write a 32-bit result and leave the upper 32 bits of the BPF register zero. The LoongArch JIT sign-extends the result of signed ALU32 BPF_DIV and BPF_MOD (off=1), so a negative 32-bit quotient or remainder leaves bits 63:32 set in JITted code while the verifier and interpreter model those bits as zero.

Keep sign-extension on the operands, which signed divide needs, and zero-extend the ALU32 result after the divide or modulo instruction, matching the unsigned ALU32 div/mod paths and every other ALU32 operation in this JIT.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 2425c9e002d2a1fdca34261b2fa6713eafef2163 to 716cb29dbed4d62e9e108950a1a82bcba4cc2d45 (excl.)
  • affected from 2425c9e002d2a1fdca34261b2fa6713eafef2163 to dacd348b8a993373576fe2ee2d8b114740ba57a6 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.7 is affected
  • unaffected from 0 to 6.7 (excl.)
  • unaffected from 7.1.6 to 7.1.* (incl.)
  • unaffected from 7.2-rc5 to * (incl.)

References