CVE-2026-53095
Description
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix abuse of kprobe_write_ctx via freplace
uprobe programs are allowed to modify struct pt_regs.
Since the actual program type of uprobe is KPROBE, it can be abused to
modify struct pt_regs via kprobe+freplace when the kprobe attaches to
kernel functions.
For example,
SEC("?kprobe")
int kprobe(struct pt_regs *regs)
{
return 0;
}
SEC("?freplace")
int freplace_kprobe(struct pt_regs *regs)
{
regs->di = 0;
return 0;
}
freplace_kprobe prog will attach to kprobe prog.
kprobe prog will attach to a kernel function.
Without this patch, when the kernel function runs, its first arg will
always be set as 0 via the freplace_kprobe prog.
To fix the abuse of kprobe_write_ctx=true via kprobe+freplace, disallow
attaching freplace programs on kprobe programs with different
kprobe_write_ctx values.
Summary dbcve.org
The Linux kernel BPF subsystem allows freplace (function replacement) programs to attach to kprobe programs. A vulnerability exists where freplace programs can bypass kprobe_write_ctx restrictions - if a kprobe has kprobe_write_ctx=true, a freplace program attached to it can also modify struct pt_regs even when it shouldn't have that permission. This allows unauthorized modification of kernel function arguments.
Mitigation
Apply the kernel patch that enforces matching kprobe_write_ctx values between kprobe and freplace programs during attachment, preventing the bypass. Ensure Linux kernel is updated to the patched version.