CVE-2026-92519 PUBLISHED

riscv, bpf: Fix memory leak in bpf_jit_free

Assigner: Linux
Reserved: 16.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

riscv, bpf: Fix memory leak in bpf_jit_free

When bpf_int_jit_compile() is called for subprograms, it returns early during the first pass (!prog->is_func || extra_pass is false), keeping ctx->offset alive for the subsequent extra pass.

If JIT compilation fails for a later subprogram, the BPF core aborts and calls bpf_jit_free() to clean up the first subprogram. However, bpf_jit_free() fails to free jit_data->ctx.offset, which causes a memory leak of the JIT context offsets array.

Fix this by adding the missing kfree(jit_data->ctx.offset) in bpf_jit_free().

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 48a8f78c50bd6f7f08fd40daa62252fd043f2f18 to b594c23f584ab032a5eae809eee81b809dd27330 (excl.)
  • affected from 48a8f78c50bd6f7f08fd40daa62252fd043f2f18 to 5cadc66b534fe8140441916200a20c7efb06a388 (excl.)
  • affected from 48a8f78c50bd6f7f08fd40daa62252fd043f2f18 to 2a3a29e90021806ea00527f6458cfd2edb58b42a (excl.)
  • affected from 48a8f78c50bd6f7f08fd40daa62252fd043f2f18 to 369e4635d04801f394d5bd42556f21029e95ff93 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.6 is affected
  • unaffected from 0 to 6.6 (excl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References