CVE-2026-93147: Linux

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: s390/bpf: Replace ly instruction with llgf cpu_nr is a 32 bit value and BPF_REG_0 is a 64 bit register, when ly loads the cpu_nr into BPF_REG_0 it does not zero the upper bits, but llgf does.

Affected products

  • Linux Linux: from 7.2, before 7.2.6 (fixed in 7.2.6)

Published 2026-09-17. Last modified 2026-09-18.