CVE-2026-31525 Details
Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN The BPF interpreter's signed 32-bit division and modulo handlers use the kernel abs() macro on s32 operands. The abs() macro documentation (include/linux/math.h) explicitly states the result is undefined when the input is the type minimum. When DST contains S32_MIN (0x80000000), abs((s32)DST) triggers undefined behavior and returns S32_MIN unchanged on arm64/x86. This value is then sign-extended to u64 as 0xFFFFFFFF80000000, causing do_div() to compute the wrong result. The verifier's abstract interpretation (scalar32_min_max_sdiv) computes the mathematically correct result for range tracking, creating a verifier/interpreter mismatch that can be exploited for out-of-bounds map value access. Introduce abs_s32() which handles S32_MIN correctly by casting to u32 before negating, avoiding signed overflow entirely. Replace all 8 abs((s32)...) call sites in the interpreter's sdiv32/smod32 handlers. s32 is the only affected case -- the s64 division/modulo handlers do not use abs().
A vulnerability in the Linux kernel's BPF interpreter has been addressed, specifically in the signed 32-bit division and modulo operations. The issue arose because these handlers used the kernel's abs() macro on signed 32-bit integers, which is undefined when the value is the minimum possible integer. On arm64 and x86 architectures, this resulted in incorrect behavior that could be exploited to access map values out of bounds. The vulnerability has been fixed by introducing a new function, abs_s32(), that correctly handles the minimum integer value, and by replacing the problematic abs() calls in the division and modulo handlers.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched kernel can be found on the official Linux kernel website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0d5d8c3ce45c734aaf3c51cbef59155a6746157d | kernel.org | Patch |
| https://git.kernel.org/stable/c/694ea55f1b1c74f9942d91ec366ae9e822422e42 | kernel.org | Patch |
| https://git.kernel.org/stable/c/9ab1227765c446942f290c83382f0b19887c55cf | kernel.org | Patch |
| https://git.kernel.org/stable/c/c77b30bd1dcb61f66c640ff7d2757816210c7cb0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f14ca604c0ff274fba19f73f1f0485c0047c1396 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.6, < 6.6.131 >= 6.7, < 6.12.80 >= 6.13, < 6.18.21 >= 6.19, < 6.19.11 7.0 rc1 7.0 rc2 7.0 rc3 7.0 rc4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Apr 28, 2026 | Initial Analysis | [email protected] |
| Apr 27, 2026 | CVE Modified | kernel.org |
| Apr 22, 2026 | New CVE Received | kernel.org |