PT-2026-98696 · Linux · Linux

CVE-2026-98033

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Preserve inner map identity in callback frames
Callback frame constructors initialize map-typed argument registers with mark reg known zero() and then restore map ptr. This clears map uid, which is the only field distinguishing inner maps that share an inner map meta template.
When a timer callback invokes bpf for each map elem() on a second inner map, both the saved first map and the second map value can reach the nested callback as the same template with map uid zero. bpf timer init() then accepts pairing the timer from the second map with the first map.
The runtime records the first map in the timer without taking a reference. Freeing that map does not find the timer stored in the second map, so a later timer callback dereferences the freed map.
Copy map uid from the same caller register as map ptr when constructing for-each, timer/workqueue, and task-work callback arguments. The existing identity check can then reject mismatched inner maps while allowing a callback value to be paired with its actual map.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98033

Produtos afetados

Linux