CVE 7.8 HIGH

bpf: Validate node_id in arena_alloc_pages()_CVE-2026-53031

7.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

bpf: Validate node_id in arena_alloc_pages()

arena_alloc_pages() accepts a plain int node_id and forwards it through
the entire allocation chain without any bounds checking.

Validate node_id before passing it down the allocation chain in
arena_alloc_pages().

Basic Information

ID CVE-2026-53031
Source Linux
Published Jun 24, 2026 at 16:29
Modified Jun 28, 2026 at 06:38

Affected Product

Vendor Linux
Product Linux
Version 317460317a02a1af512697e6e964298dedd8a163
Affected Versions Linux Linux 317460317a02a1af512697e6e964298dedd8a163
Linux Linux 317460317a02a1af512697e6e964298dedd8a163
Linux Linux 317460317a02a1af512697e6e964298dedd8a163
Linux Linux 317460317a02a1af512697e6e964298dedd8a163
Linux Linux 6.9

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.