Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
High

Linux kernel BPF tcx/netkit unauthorized detach permission bypass

IdentifiersCVE-2026-45932CWE-862

CVE-2026-45932 is a local privilege/authorization flaw in the Linux kernel BPF detach path affecting tcx and netkit devices. When BPF_PROG_DETACH was invoked without supplying a program file descriptor, the kernel failed to enforce the intended permission checks, allowing the detach operation to proceed for unprivileged users. The issue is described in the upstream fix as: "bpf: Fix tcx/netkit detach permissions when prog fd isn't given." The remediation adds an explicit capability check requiring CAP_NET_ADMIN or CAP_SYS_ADMIN when no program fd is provided.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

A local attacker with low privileges and no user interaction can bypass authorization checks and detach BPF programs from tcx or netkit devices. This can undermine networking policy enforcement or other security controls implemented through attached BPF programs, with resulting confidentiality impact reported as low and integrity and availability impact reported as high. Published scoring in the provided content lists CVSS v3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H.

Mitigation

If you can’t patch tonight, do this now.

No specific workaround is provided in the supplied content beyond applying the vendor fix. Until patched, restrict local shell and container access to trusted users, minimize exposure of BPF-related administrative interfaces, and ensure only appropriately privileged users can perform networking administration. Where operationally feasible, monitor for unexpected BPF program detach activity on tcx or netkit devices.

Remediation

Patch, then assume compromise.

Update to a Linux kernel version containing the fix for CVE-2026-45932. The fix adds a capability check requiring CAP_NET_ADMIN or CAP_SYS_ADMIN for BPF_PROG_DETACH on tcx or netkit devices when no program file descriptor is supplied. In the provided vendor context, fixed SUSE package versions include, for example, SUSE Linux Enterprise Server 16.0 and openSUSE Leap 16.0 kernel packages at 6.12.0-160000.35.1 or later, SLE 15 SP6-LTSS kernel packages at 6.4.0-150600.23.118.1 or later, SLE Desktop 15 SP7 kernel packages at 6.4.0-150700.53.60.1 or later, and SUSE Linux Micro 6.0/6.1 kernel-default at 6.4.0-47.1 or later.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
LinuxLinux Kerneloperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

ACTIVITY FEED

Recent activity

6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.

No news coverage yet. Advisories and community discussion only.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.