{"id":"CVE-2026-89906","published":"2026-09-16T11:16:59.590","lastModified":"2026-09-16T15:18:16.683","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: BPF: Refactor jump offset calculation in tail call\n\nThe old macro-based jmp_offset calculation derives the jump distance\nfrom a stale prior-pass code stride, which can lead to wrong branch\noffsets and soft lockups under extra JIT passes.\n\nFix this by calculating the offset directly on the absolute target:\n\"ctx->offset[insn + 1] - ctx->idx\".\n\nTo avoid a false 16-bit range check abort during size estimation, add\na \"ctx->image == NULL\" guard to inject a safe dummy offset.","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/37d545d12f21c4d50612ecaebd7ae1e5bf91b2d8","tags":[]},{"url":"https://git.kernel.org/stable/c/882b8912b7e92341fdb115ba0e2e5142a28684ff","tags":[]},{"url":"https://git.kernel.org/stable/c/96f44d493c280ea161569c43d7ed0f3b0815803a","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}