ThreatCluster

Multiple CVEs Address bpf Overflow Checks

First seen 18 Feb 2026, 09:15 UTC Api.Msrc.Microsoft 47

Article Content

Browse articles
ThreatCluster

On February 18, 2026, Microsoft published information regarding three CVEs related to the bpf (Berkeley Packet Filter) subsystem. The vulnerabilities, CVE-2024-26885, CVE-2024-26884, and CVE-2024-26883, involve overflow checks on DEVMAP_HASH, hashtab, and stackmap, respectively, all affecting 32-bit systems. These vulnerabilities were officially published on April 17, 2024.

Timeline

2024-04-17
CVE-2024-26885 published
2024-04-17
CVE-2024-26884 published
2024-04-17
CVE-2024-26883 published
2026-02-18
Information published regarding CVEs