Habr•September 8, 2026•🇷🇺Translated from Russian

eBPF Verifier Discrepancy Revealed: PREVAIL Accepts Safe Code Rejected by Linux Kernel Verifier

Security researchers examining the eBPF verifier encountered a case where two independent static analyzers reached opposite conclusions about the same object file. The program correlated_branch.c from the ebpf-samples repository was accepted by the external verifier PREVAIL yet rejected by the in-kernel Linux verifier during loading via bpftool.

The test was performed on Ubuntu 24.04.1 LTS with kernel Linux 6.14.0-37-generic and clang 18.1.3 targeting the bpf architecture. The XDP function ConvergedBranch first obtains packet boundaries from the context, calls check_packet to verify that at least 14 bytes are available, and only then dereferences the Ethernet header type field at offset 12.

The kernel verifier log shows that the scalar register holding the computed length receives the constraint R2_w=scalar(smin=umin=14,...) after the comparison. However, the pointer stored in r7 is not annotated with a matching packet offset range, causing the subsequent load r3 = *(u16 *)(r7 + 12) to be rejected as an invalid packet access.

In contrast, PREVAIL records the state r7.type=packet packet_size=14 r7.packet_offset=0 after the same check. When the load instruction is reached, the tool evaluates assert valid_access(r7.offset+12, width=2) and permits the read because the offset plus size fits inside the proven 14-byte region.

The root cause is architectural: the kernel verifier treats the length scalar and the packet pointer as separate abstract domains, while PREVAIL preserves relational information across states. When the bounds check was inlined directly in ConvergedBranch instead of being hidden inside check_packet, the kernel verifier successfully accepted the program.

The episode demonstrates that a verifier rejection does not automatically imply the presence of a memory-safety bug. Analysts must examine register states such as R7 pkt(off=0,r=0) to determine whether the required offset range was simply not propagated.

Related articles

Hispasec•Vulnerabilities & Exploits

CISA Sets September 30 Deadline for Federal Agencies to Patch Actively Exploited Citrix NetScaler Zero-Days

CISA has ordered U.S. federal agencies to apply patches by September 30 for two actively exploited zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, enable unauthenticated remote code execution under default configurations and affect systems commonly exposed to the internet. CVE-2026-88771 allows remote code execution without authentication on NetScaler ADC and Gateway, while CVE-2026-88772 can trigger remote code execution or denial of service via a memory overflow when DTLS is enabled on VPN vServers. Citrix has released fixes for versions 14.1 and 13.1, including FIPS and NDcPP builds, with minimum required builds of 14.1-73.37 and 13.1-64.23. The advisory also covers six additional vulnerabilities from CVE-2026-88773 to CVE-2026-88778 involving HTTP request smuggling and TCP ISN prediction issues. Unsupported branches NetScaler 12.1 and 13.0 receive no patches, requiring immediate migration. Organizations are advised to inventory instances, check for compromise indicators before patching, and preserve forensic evidence.

BoletimSec•Vulnerabilities & Exploits

CSRF Flaw in Elementor Allows Admin Account Creation on Over 2 Million WordPress Sites

A critical CSRF vulnerability has been identified in the Elementor page builder plugin for WordPress, affecting versions 4.3.0 and 4.3.1. The issue enables attackers to create administrator accounts on target sites by exploiting improper handling of CSRF protections in the Editor Events module. With a CVSS score of 8.8, the flaw impacts more than 2 million installations out of over 10 million total WordPress sites using the plugin. No CVE identifier had been assigned at the time of disclosure on September 26. The vulnerability was fixed in version 4.3.2, and users are urged to update immediately. The discovery is credited to researcher Saggre following responsible disclosure, with no public records of active exploitation noted at the time of analysis.

BoletimSec•Vulnerabilities & Exploits

Mandiant Uncovers WAF Bypass Campaign Exploiting Critical Oracle PeopleSoft CVE-2026-35273

Mandiant has identified an active campaign abusing CVE-2026-35273, a critical unauthenticated remote code execution flaw in Oracle PeopleSoft's Environment Management Hub (PSEMHUB). Attackers bypass web application firewalls by replacing the literal path /PSEMHUB/ with /%50SEMHUB/, exploiting the fact that many WAF rules inspect the URL before decoding while the PeopleSoft application server decodes it afterward. The exploitation chain relies on Java object deserialization via POST requests to /%50SEMHUB/hub, allowing deployment of two distinct JSP web shells. The group then establishes persistence with a trojanized installer that drops the SIDEEYE backdoor along with Neo-reGeorg and MeshAgent. Activity attributed to UNC6240, linked to ShinyHunters, began as a zero-day against educational institutions in June 2026 and has since expanded to higher education, technology, healthcare, agriculture, transportation, and government sectors.

Habr•Vulnerabilities & Exploits

Dissecting CVE-2026-83557 in jackson-databind: Why Not Every CVE Requires Immediate Panic

A detailed analysis of CVE-2026-83557 reveals that the vulnerability in jackson-databind affects only a narrow set of configurations involving polymorphic deserialization with the Comparable base type. The flaw stems from an incomplete denylist in DefaultBaseTypeLimitingValidator, which overlooks java.lang.Comparable when the MapperFeature.BLOCK_UNSAFE_POLYMORPHIC_BASE_TYPES flag is explicitly enabled. Researchers constructed working proof-of-concept exploits showing that an attacker can instantiate classes such as java.io.File, but only when the property is declared as Comparable<?> and the protective flag is active. The issue impacts versions 2.11 through 2.22.1, yet the CVSS score of 5.6 reflects its moderate real-world risk because most applications lack the required Comparable-typed polymorphic fields. Patching introduces its own trade-off by blocking legitimate Comparable subclasses, forcing developers to implement custom BasicPolymorphicTypeValidator allowlists. The case highlights how dependency scanners often flag CVEs without considering application-specific configuration and DTO structures.