LiveActive security incident?Get immediate response
CVE Record

CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject sleepable kprobe_multi programs at attach time kprobe.multi programs run in atomic/RCU context and cannot sleep. However, bpf_kprobe_multi_link_attach() did not validate whether the program being attached had the sleepable flag set, allowing sleepable helpers such as bpf_copy_from_user() to be invoked from a non-sleepable context. This causes a "sleeping function called from invalid context" splat: BUG: sleeping function called from invalid context at ./include/linux/uaccess.h:169 in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 1787, name: sudo preempt_count: 1, expected: 0 RCU nest depth: 2, expected: 0 Fix this by rejecting sleepable programs early in bpf_kprobe_multi_link_attach(), before any further processing.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2026-43010 is a Linux kernel eBPF validation flaw. A sleepable BPF program could be attached to kprobe_multi even though that context cannot sleep, triggering a kernel warning/BUG condition. Public sources do not show active exploitation or a CVSS score.

Executive priority

Treat as a routine-to-priority Linux kernel maintenance item, higher for platforms that permit eBPF use by non-administrative workloads. There is no public evidence of active exploitation, but kernel stability risk justifies timely patch planning.

Technical view

bpf_kprobe_multi_link_attach() failed to reject BPF programs marked sleepable. kprobe.multi runs in atomic/RCU context, so helpers such as bpf_copy_from_user() can cause “sleeping function called from invalid context.” The upstream fix rejects sleepable programs at attach time before further processing.

Likely exposure

Exposure is likely limited to Linux systems where users or processes can load and attach eBPF kprobe_multi programs. Prioritize hosts running affected kernel versions listed in the CVE record and systems with delegated BPF capabilities.

Exploitation context

No cited source reports active exploitation, and the CVE is not marked KEV. The described impact is a kernel splat from invalid sleepable behavior in atomic/RCU context. Sources do not provide evidence of privilege escalation or remote exploitation.

Researcher notes

The record identifies the missing attach-time validation in bpf_kprobe_multi_link_attach(). Affected-version data is not fully clear from the bundle, so confirm against distribution advisories and the referenced stable commits. Avoid assuming exploitability beyond the documented invalid-context kernel warning.

Mitigation direction

  • Apply the relevant Linux stable kernel update containing the referenced fix.
  • Map distribution kernel packages to the upstream stable commits before deployment.
  • Restrict eBPF loading and attachment privileges where operationally feasible.
  • Monitor vendor advisories for backported fixes and affected version clarification.

Validation and detection

  • Inventory Linux kernel versions across servers, containers hosts, and appliances.
  • Check whether deployed kernels include one of the referenced stable commits.
  • Review which users or services can load and attach eBPF programs.
  • Look for kernel logs mentioning “sleeping function called from invalid context.”
Prepared
Confidence
medium
Sources
7

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2026-43010 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
0ADP providers
6Source links

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux0dcac272540613d41c05e89679e4ddb978b612f1, 0dcac272540613d41c05e89679e4ddb978b612f1, 0dcac272540613d41c05e89679e4ddb978b612f1, 0dcac272540613d41c05e89679e4ddb978b612f1, 0dcac272540613d41c05e89679e4ddb978b612f1unaffected
LinuxLinux5.18, 0, 6.6.144, 6.12.95, 6.18.22, 6.19.12, 7.0affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.