PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-52938 Linux CVE debrief

A vulnerability was found in the Linux kernel, specifically related to a NULL pointer dereference in bpf_sk_storage_clone and diag paths. The issue arises when bpf_selem_unlink_nofail() sets SDATA(selem)->smap to NULL before removing the selem from the storage hlist. A concurrent RCU reader in bpf_sk_storage_clone() can observe the selem still on the list with smap already NULL, causing a NULL pointer dereference. The vulnerability has been resolved by adding a NULL check for smap in bpf_sk_storage_clone(). This fix prevents the NULL pointer dereference by ensuring that the smap is validated before being used.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-24
Original CVE updated
2026-07-08
Advisory published
2026-06-24
Advisory updated
2026-07-08

Who should care

Users of the Linux kernel should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes reviewing system configurations, applying patches, and monitoring for updates. The vulnerability affects the Linux kernel and could potentially be exploited by attackers to cause a denial of service or execute arbitrary code.

Technical summary

The vulnerability is caused by a NULL pointer dereference in bpf_sk_storage_clone and diag paths. The issue arises when bpf_selem_unlink_nofail() sets SDATA(selem)->smap to NULL before removing the selem from the storage hlist. A concurrent RCU reader in bpf_sk_storage_clone() can observe the selem still on the list with smap already NULL, causing a NULL pointer dereference. The fix involves adding a NULL check for smap in bpf_sk_storage_clone() and bpf_sk_storage_diag_put_all(). Additionally, bpf_sk_storage_diag_put() uses diag->maps[i] which is always valid under its refcount, so diag->maps[i] is passed directly to diag_get().

Defensive priority

High

Recommended defensive actions

  • Apply the patch
  • Monitor for updates
  • Review system configurations
  • Verify system exposure
  • Check relevant monitoring and logs
  • Track exceptions and retest remediated assets

Evidence notes

The vulnerability was resolved by adding a NULL check for smap in bpf_sk_storage_clone(). This fix addresses a NULL pointer dereference issue that occurs when bpf_selem_unlink_nofail() sets SDATA(selem)->smap to NULL before removing the selem from the storage hlist, and a concurrent RCU reader in bpf_sk_storage_clone() observes the selem still on the list with smap already NULL. The fix ensures that the smap is validated before being used, preventing the NULL pointer dereference. Evidence is based on the Linux kernel patch notes and vulnerability analysis.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-52938 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-52938

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-52938 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52938

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/16af24fea29c209dea53595c99f6da9398548e1b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/375e4e33c18dfa05c5dfd5f3dfffeb29343dd4c7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.