{"cve":{"cve_id":"CVE-2026-53081","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":null,"epss_percentile":null,"epss_as_of":null,"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars\n\nWhen regsafe() compares two scalar registers that both carry\nBPF_ADD_CONST, check_scalar_ids() maps their full compound id\n(aka base | BPF_ADD_CONST flag) as one idmap entry. However,\nit never verifies that the underlying base ids, that is, with\nthe flag stripped are consistent with existing idmap mappings.\n\nThis allows construction of two verifier states where the old\nstate has R3 = R2 + 10 (both sharing base id A) while the current\nstate has R3 = R4 + 10 (base id C, unrelated to R2). The idmap\ncreates two independent entries: A->B (for R2) and A|flag->C|flag\n(for R3), without catching that A->C conflicts with A->B. State\npruning then incorrectly succeeds.\n\nFix this by additionally verifying base ID mapping consistency\nwhenever BPF_ADD_CONST is set: after mapping the compound ids,\nalso invoke check_ids() on the base IDs (flag bits stripped).\nThis ensures that if A was already mapped to B from comparing\nthe source register, any ADD_CONST derivative must also derive\nfrom B, not an unrelated C.","published_at":"2026-06-24T16:30:21.959000Z","last_modified_at":null,"cvss_v3_score":7.8,"cvss_v3_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvss_v3_severity":"HIGH","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":null,"ssvc_automatable":null,"ssvc_technical_impact":null,"cwes":null,"nvd_references":["https://git.kernel.org/stable/c/13c02881e49aac4c82b261faa26db9edf2567231","https://git.kernel.org/stable/c/691adf738817275368ed56311b7d798d617823a3","https://git.kernel.org/stable/c/7d73c72cccac651acc891377a5e623e4021c6380","https://git.kernel.org/stable/c/2f2ec8e7730e21fc9bd49e0de9cdd58213ea24d0"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-28T17:55:28.590503Z","updated_at":"2026-06-28T23:30:50.753831Z"},"effective_severity":"HIGH","badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"L","value_label":"Local"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"L","value_label":"Low"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"H","value_label":"High"},{"metric":"A","name":"Availability","value":"H","value_label":"High"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"98d7ca374ba4b39e7535613d40e159f09ca14da2","version_start_inclusive":true,"version_end":"13c02881e49aac4c82b261faa26db9edf2567231","version_end_inclusive":false,"cpe23_uri":"cve5:linux:linux:98d7ca374ba4b39e7535613d40e159f09ca14da2:13c02881e49aac4c82b261faa26db9edf2567231"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"98d7ca374ba4b39e7535613d40e159f09ca14da2","version_start_inclusive":true,"version_end":"691adf738817275368ed56311b7d798d617823a3","version_end_inclusive":false,"cpe23_uri":"cve5:linux:linux:98d7ca374ba4b39e7535613d40e159f09ca14da2:691adf738817275368ed56311b7d798d617823a3"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"98d7ca374ba4b39e7535613d40e159f09ca14da2","version_start_inclusive":true,"version_end":"7d73c72cccac651acc891377a5e623e4021c6380","version_end_inclusive":false,"cpe23_uri":"cve5:linux:linux:98d7ca374ba4b39e7535613d40e159f09ca14da2:7d73c72cccac651acc891377a5e623e4021c6380"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"98d7ca374ba4b39e7535613d40e159f09ca14da2","version_start_inclusive":true,"version_end":"2f2ec8e7730e21fc9bd49e0de9cdd58213ea24d0","version_end_inclusive":false,"cpe23_uri":"cve5:linux:linux:98d7ca374ba4b39e7535613d40e159f09ca14da2:2f2ec8e7730e21fc9bd49e0de9cdd58213ea24d0"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"6.11","version_start_inclusive":true,"version_end":"6.11","version_end_inclusive":true,"cpe23_uri":"cve5:linux:linux:6.11:6.11"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"0","version_start_inclusive":true,"version_end":"6.11","version_end_inclusive":false,"cpe23_uri":"cve5:linux:linux:0:6.11"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"6.12.91","version_start_inclusive":true,"version_end":"6.12.*","version_end_inclusive":true,"cpe23_uri":"cve5:linux:linux:6.12.91:6.12.*"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"6.18.33","version_start_inclusive":true,"version_end":"6.18.*","version_end_inclusive":true,"cpe23_uri":"cve5:linux:linux:6.18.33:6.18.*"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"7.0.10","version_start_inclusive":true,"version_end":"7.0.*","version_end_inclusive":true,"cpe23_uri":"cve5:linux:linux:7.0.10:7.0.*"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"7.1","version_start_inclusive":true,"version_end":"*","version_end_inclusive":true,"cpe23_uri":"cve5:linux:linux:7.1:*"}],"exploit_refs":[],"news":[],"references":[{"url":"https://git.kernel.org/stable/c/13c02881e49aac4c82b261faa26db9edf2567231","source_type":"MISC","tags":[]},{"url":"https://git.kernel.org/stable/c/691adf738817275368ed56311b7d798d617823a3","source_type":"MISC","tags":[]},{"url":"https://git.kernel.org/stable/c/7d73c72cccac651acc891377a5e623e4021c6380","source_type":"MISC","tags":[]},{"url":"https://git.kernel.org/stable/c/2f2ec8e7730e21fc9bd49e0de9cdd58213ea24d0","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2026-06-24T16:30:21.959000Z","label":"CVE published","source":null}]}