AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-68295

HIGH · CVSS 7.8 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's LoongArch architecture, specifically in the handling of signed ALU32 division and modulo operations within the BPF (Berkeley Packet Filter) context. This flaw allows negative results to improperly extend into the upper bits of the BPF register, potentially leading to incorrect program behavior or security issues. Organizations utilizing the Linux kernel on LoongArch platforms should prioritize addressing this vulnerability to ensure the integrity and reliability of their applications.

CVE
CVE-2026-68295
Severity
HIGH
CVSS
7.8
EPSS
0.15%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Zero-extend signed ALU32 div/mod results ALU32 operations write a 32-bit result and leave the upper 32 bits of the BPF register zero. The LoongArch JIT sign-extends the result of signed ALU32 BPF_DIV and BPF_MOD (off=1), so a negative 32-bit quotient or remainder leaves bits 63:32 set in JITted code while the verifier and interpreter model those bits as zero. Keep sign-extension on the operands, which signed divide needs, and zero-extend the ALU32 result after the divide or modulo instruction, matching the unsigned ALU32 div/mod paths and every other ALU32 operation in this JIT.