{"schema_version":"1.7.2","id":"OESA-2026-2931","modified":"2026-07-09T12:53:14Z","published":"2026-07-09T12:53:14Z","upstream":["CVE-2026-45886"],"summary":"kernel security update","details":"The Linux Kernel, the operating system core itself.\r\n\r\nSecurity Fix(es):\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix bpf_xdp_store_bytes proto for read-only arg\n\nWhile making some maps in Cilium read-only from the BPF side, we noticed\nthat the bpf_xdp_store_bytes proto is incorrect. In particular, the\nverifier was throwing the following error:\n\n  ; ret = ctx_store_bytes(ctx, l3_off + offsetof(struct iphdr, saddr),\n                          &amp;nat-&gt;address, 4, 0);\n  635: (79) r1 = *(u64 *)(r10 -144)     ; R1=ctx() R10=fp0 fp-144=ctx()\n  636: (b4) w2 = 26                     ; R2=26\n  637: (b4) w4 = 4                      ; R4=4\n  638: (b4) w5 = 0                      ; R5=0\n  639: (85) call bpf_xdp_store_bytes#190\n  write into map forbidden, value_size=6 off=0 size=4\n\nnat comes from a BPF_F_RDONLY_PROG map, so R3 is a PTR_TO_MAP_VALUE.\nThe verifier checks the helper&apos;s memory access to R3 in\ncheck_mem_size_reg, as it reaches ARG_CONST_SIZE argument. The third\nargument has expected type ARG_PTR_TO_UNINIT_MEM, which includes the\nMEM_WRITE flag. The verifier thus checks for a BPF_WRITE access on R3.\nGiven R3 points to a read-only map, the check fails.\n\nConversely, ARG_PTR_TO_UNINIT_MEM can also lead to the helper reading\nfrom uninitialized memory.\n\nThis patch simply fixes the expected argument type to match that of\nbpf_skb_store_bytes.(CVE-2026-45886)","affected":[{"package":{"ecosystem":"openEuler:24.03-LTS-SP3","name":"kernel","purl":"pkg:rpm/openEuler/kernel&distro=openEuler-24.03-LTS-SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{}]}],"ecosystem_specific":{"aarch64":["bpftool-6.6.0-145.3.18.151.oe2403sp3.aarch64.rpm","bpftool-debuginfo-6.6.0-145.3.18.151.oe2403sp3.aarch64.rpm","kernel-6.6.0-145.3.18.151.oe2403sp3.aarch64.rpm","kernel-debuginfo-6.6.0-145.3.18.151.oe2403sp3.aarch64.rpm","kernel-debugsource-6.6.0-145.3.18.151.oe2403sp3.aarch64.rpm","kernel-devel-6.6.0-145.3.18.151.oe2403sp3.aarch64.rpm","kernel-extra-modules-6.6.0-145.3.18.151.oe2403sp3.aarch64.rpm","kernel-headers-6.6.0-145.3.18.151.oe2403sp3.aarch64.rpm","kernel-source-6.6.0-145.3.18.151.oe2403sp3.aarch64.rpm","kernel-tools-6.6.0-145.3.18.151.oe2403sp3.aarch64.rpm","kernel-tools-debuginfo-6.6.0-145.3.18.151.oe2403sp3.aarch64.rpm","kernel-tools-devel-6.6.0-145.3.18.151.oe2403sp3.aarch64.rpm","perf-6.6.0-145.3.18.151.oe2403sp3.aarch64.rpm","perf-debuginfo-6.6.0-145.3.18.151.oe2403sp3.aarch64.rpm","python3-perf-6.6.0-145.3.18.151.oe2403sp3.aarch64.rpm","python3-perf-debuginfo-6.6.0-145.3.18.151.oe2403sp3.aarch64.rpm"],"x86_64":["bpftool-6.6.0-145.3.18.151.oe2403sp3.x86_64.rpm","bpftool-debuginfo-6.6.0-145.3.18.151.oe2403sp3.x86_64.rpm","kernel-6.6.0-145.3.18.151.oe2403sp3.x86_64.rpm","kernel-debuginfo-6.6.0-145.3.18.151.oe2403sp3.x86_64.rpm","kernel-debugsource-6.6.0-145.3.18.151.oe2403sp3.x86_64.rpm","kernel-devel-6.6.0-145.3.18.151.oe2403sp3.x86_64.rpm","kernel-extra-modules-6.6.0-145.3.18.151.oe2403sp3.x86_64.rpm","kernel-headers-6.6.0-145.3.18.151.oe2403sp3.x86_64.rpm","kernel-source-6.6.0-145.3.18.151.oe2403sp3.x86_64.rpm","kernel-tools-6.6.0-145.3.18.151.oe2403sp3.x86_64.rpm","kernel-tools-debuginfo-6.6.0-145.3.18.151.oe2403sp3.x86_64.rpm","kernel-tools-devel-6.6.0-145.3.18.151.oe2403sp3.x86_64.rpm","perf-6.6.0-145.3.18.151.oe2403sp3.x86_64.rpm","perf-debuginfo-6.6.0-145.3.18.151.oe2403sp3.x86_64.rpm","python3-perf-6.6.0-145.3.18.151.oe2403sp3.x86_64.rpm","python3-perf-debuginfo-6.6.0-145.3.18.151.oe2403sp3.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2931"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45886"}],"database_specific":{"severity":"Medium"}}
