PT-2026-98747 · Linux · Linux

CVE-2026-98084

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
bpf: backtracking shouldn't clear outer frame R1-R5 for callbacks
When processing calls to bpf loop() verifier marks R1 (and R4) as precise. R1 tracks loop iterations number and because of the 'callback depth < R1' mechanics in check helper call() must be marked precise. However, precision propagation for R1 was broken, when bpf loop() call was verified on a second iteration.
Consider the following verification trace:
  • main: bpf loop(nr loops, callback ...)
  • callback: BPF EXIT
  • main: bpf loop(nr loops, callback ...)
  • ...
While the first visit of the call to bpf loop() propagated R1 precision as expected, the second call to mark chain precision() in the check helper call() set R1, but it was immediately reset when backtrack insn() processed preceding BPF EXIT in the loop deleted in this patch.
Because of that, the second visit of the call to bpf loop() injected checkpoint with R1 not marked as precise. Which could trick the verifier into accepting unsafe programs. See the next patch for an example of such program.
Commit is structured in a way to minimize conflicts when 'bpf' would be eventually merged with 'bpf-next'.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98084

Produtos afetados

Linux