Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Zero-extend signed ALU32 div/mod results ALU32 operations write a 32-bit result and leave the upper 32 bits of the BPF register zero. The LoongArch JIT sign-extends the result of signed ALU32 BPF_DIV and BPF_MOD (off=1), so a negative 32-bit quotient or remainder leaves bits 63:32 set in JITted code while the verifier and interpreter model those bits as zero. Keep sign-extension on the operands, which signed divide needs, and zero-extend the ALU32 result after the divide or modulo instruction, matching the unsigned ALU32 div/mod paths and every other ALU32 operation in this JIT.
CVSS Score
HIGH
References
- https://git.kernel.org/stable/c/716cb29dbed4d62e9e108950a1a82bcba4cc2d45
- https://git.kernel.org/stable/c/dacd348b8a993373576fe2ee2d8b114740ba57a6
FAQ
What is CVE-2026-68295?
CVE-2026-68295 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Zero-extend signed ALU32 div/mod results ALU32 operations write a 32-bit result and leave the upper 32 bits of the...
How severe is CVE-2026-68295?
CVE-2026-68295 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-68295?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.