CVE-2026-53670

PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, in the Prevail eBPF verifier, EbpfTransformer::add() silently skips offset-variable updates when the destination register carries a non-singleton typeset (two or more simultaneously possible pointer types). Subsequent bounds checks use the stale offset and accept out-of-bounds memory accesses, so a crafted BPF program passes verification even though it would corrupt memory at runtime. This issue has been patched in version 0.2.4.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 18:20

Updated : 2026-09-09 16:49


NVD link : CVE-2026-53670

Mitre link : CVE-2026-53670

CVE.ORG link : CVE-2026-53670


JSON object : View

Products Affected

No product.

CWE
CWE-682

Incorrect Calculation