PT-2026-98670 · Linux · Linux

CVE-2026-98007

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject non-scalar bpf loop iteration counts
bpf loop() declares its nr loops argument as ARG ANYTHING. Privileged programs may pass pointer values to such arguments, so check func arg() lets a pointer-valued R1 reach the helper-specific checks.
Since commit bb124da69c47 ("bpf: keep track of max number of bpf loop callback iterations"), the verifier marks R1 precise and reads its upper bound to limit callback simulation. Precision backtracking only accepts scalar registers, so passing a pointer instead triggers the "backtracking misuse" verifier warning. Kernels with panic on warn enabled subsequently panic.
Introduce ARG SCALAR for helper arguments that only accept scalar values and use it for bpf loop() nr loops. Generic helper argument validation then rejects pointers before loop inlining and precision processing.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98007

Produtos afetados

Linux