PT-2026-98670 · Linux · Linux
CVE-2026-98007
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject non-scalar bpf loop iteration counts
bpf loop() declares its nr loops argument as ARG ANYTHING. Privileged
programs may pass pointer values to such arguments, so check func arg()
lets a pointer-valued R1 reach the helper-specific checks.
Since commit bb124da69c47 ("bpf: keep track of max number of bpf loop
callback iterations"), the verifier marks R1 precise and reads its upper
bound to limit callback simulation. Precision backtracking only accepts
scalar registers, so passing a pointer instead triggers the "backtracking
misuse" verifier warning. Kernels with panic on warn enabled subsequently
panic.
Introduce ARG SCALAR for helper arguments that only accept scalar values
and use it for bpf loop() nr loops. Generic helper argument validation then
rejects pointers before loop inlining and precision processing.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux