[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-53671":6},{"stargazers_count":4,"fetched_at":5},7,"2026-09-02T23:44:56.672Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":28,"aliases":29,"duplicate_of":9,"upstream":30,"downstream":31,"duplicates":32,"related":33,"reserved_at":9,"published_at":34,"modified_at":34,"state":35,"summary":36,"references_raw":43,"kevs":59,"epss":9,"epss_history":60,"metrics":61,"affected":68},"CVE-2026-53671","PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstract transformer in prevail treats writes through a T_CTX-typed base register as a silent no-op: do_mem_store in src/crab/ebpf_transformer.cpp only models T_STACK stores, and the checker's T_CTX bounds arm never tests AccessType::write. An attacker can craft an eBPF program that overwrites a context field (e.g., ctx->data), reload that field typed as T_PACKET, and dereference an attacker-controlled address — and prevail will report the program as safe. This issue has been patched in version 0.2.4.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-682","Incorrect Calculation","The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.","weakness","Draft","Pillar","High",[20,24],{"id":21,"name":22,"techniques":23},"CAPEC-128","Integer Attacks",[],{"id":25,"name":26,"techniques":27},"CAPEC-129","Pointer Manipulation",[],[],[],[],[],[],[],"2026-09-02T17:54:30.682Z","Received",{"cisa_kev":37,"cisa_ransomware":37,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":38,"severity_score":39,"severity_version":40,"severity_source":41,"severity_vector":42,"severity_status":35},false,"critical",9.3,"v4.0","cve.org","CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",[44,50,55],{"url":45,"sources":46,"tags":48},"https://github.com/vbpf/prevail/security/advisories/GHSA-65rv-h458-cq99",[41,47],"nvd",[49],"X Refsource CONFIRM",{"url":51,"sources":52,"tags":53},"https://github.com/vbpf/prevail/commit/de65234f67d2608b54d12571edb585ead224363c",[41,47],[54],"X Refsource MISC",{"url":56,"sources":57,"tags":58},"https://github.com/vbpf/prevail/releases/tag/v0.2.4",[41,47],[54],[],[],[62,65],{"source":41,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":63},{"baseScore":39,"baseSeverity":64,"vectorString":42,"impactScore":9,"exploitabilityScore":9},"CRITICAL",{"source":47,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":66},{"baseScore":39,"baseSeverity":64,"vectorString":67,"impactScore":9,"exploitabilityScore":9},"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",[69],{"ecosystem":9,"name":70,"vendor":71,"product":70,"cpe_part":72,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":73},"prevail","vbpf","a",[74],{"version":75,"is_range":76,"range_type":41,"version_start":9,"version_start_type":9,"version_end":77,"version_end_type":78,"fixed_in":9},"\u003C 0.2.4",true,"0.2.4","excluding"]