CVE-2026-92518: Linux

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix kernel stack corruption in tailcall with CFI When CONFIG_CFI_CLANG is enabled, prog->bpf_func already skips the kcfi instruction during setup. Including it again in the tailcall jump offset causes it to jump over an extra 4 bytes, skipping the stack pointer adjustment, which will result in kernel stack corruption.

Affected products

  • Linux Linux: from 6.11.6, before 6.12 (fixed in 6.12); from 6.12, before 6.18.52 (fixed in 6.18.52); from 6.19, before 7.2.6 (fixed in 7.2.6)

Published 2026-09-17. Last modified 2026-09-18.