Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a potential use-after-free of BTF object Refcounting in the check_pseudo_btf_id() function is incorrect: the __check_pseudo_btf_id() function might get called with a zero refcounted btf. Fix this, and patch related code accordingly. v3: rephrase a comment (AI) v2: fix a refcount leak introduced in v1 (AI)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.14, < 6.18.14 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/9ff46ffeecdb1802d6e26183177935b948a12e7fPatch
- https://git.kernel.org/stable/c/ccd2d799ed4467c07f5ee18c2f5c59bcc990822cPatch
- https://git.kernel.org/stable/c/eac65c272f3b49021a843cba5107d63627395e0ePatch
FAQ
What is CVE-2026-45951?
CVE-2026-45951 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a potential use-after-free of BTF object Refcounting in the check_pseudo_btf_id() function is incorrect: the __check_pseu...
How severe is CVE-2026-45951?
CVE-2026-45951 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45951?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.