{"id":"CVE-2026-72402","summary":"bpf: Mask pseudo pointer values in verifier logs","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Mask pseudo pointer values in verifier logs\n\nprint_bpf_insn() masks ldimm64 immediates for pointer-bearing pseudo\nsources when pointer leaks are not allowed, but the mask only covers\nBPF_PSEUDO_MAP_FD and BPF_PSEUDO_MAP_VALUE.\n\nBPF_PSEUDO_MAP_IDX, BPF_PSEUDO_MAP_IDX_VALUE, and BPF_PSEUDO_BTF_ID can\nalso be resolved to kernel pointer values before the verifier log prints\nthe instruction. Include them in the existing pointer classification so\nthe log prints 0x0 instead of the rewritten address.","modified":"2026-10-05T02:30:20.635510054Z","published":"2026-08-15T05:56:26.816Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72402.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/1c53d16b174dd9e02243fc0e85089e2aa6a0d21a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6181239115e19cda4b483a2604193a9379cbd28f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/72a85e9464a5332fb2cd7efd26d9295275ceda2d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b767a5d7c6cb595f9feb00b5af96191a59efca26"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b96cb1235fcaa687291b1e1d910f0930d1939919"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c727b3d50ecb0f4992a964360771040a84026914"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72402.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72402"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"4976b718c3551faba2c0616ef55ebeb74db1c5ca"},{"fixed":"b767a5d7c6cb595f9feb00b5af96191a59efca26"},{"fixed":"6181239115e19cda4b483a2604193a9379cbd28f"},{"fixed":"c727b3d50ecb0f4992a964360771040a84026914"},{"fixed":"b96cb1235fcaa687291b1e1d910f0930d1939919"},{"fixed":"1c53d16b174dd9e02243fc0e85089e2aa6a0d21a"},{"fixed":"72a85e9464a5332fb2cd7efd26d9295275ceda2d"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72402.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.10.0"},{"fixed":"6.1.189"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.158"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.111"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.53"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72402.json"}}],"schema_version":"1.9.0"}