PT-2026-108764 · Linux · Linux
CVE-2026-98378
·
Published
2026-10-09
·
Updated
2026-10-09
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Skip unsettled links in link iterator
bpf link prime() inserts a link into link idr before anon inode getfile()
succeeds and before bpf link settle() publishes the ID in link->id.
bpf link by id() treats such an ID-zero link as unsettled, but the link
iterator takes a reference without this check.
If anon inode getfile() then fails, the creator removes the ID and frees
its still-private link directly. The iterator is left with a dangling
reference and its next bpf link put() accesses freed memory.
Treat ID-zero entries as transient in bpf link get curr or next(), just as
bpf link by id() does.
BUG: KASAN: slab-use-after-free in bpf link put
Write of size 8 by task exp/384
Call Trace:
bpf link put kernel/bpf/syscall.c:3372
bpf link seq next kernel/bpf/link iter.c:33
bpf seq read kernel/bpf/bpf iter.c:158
vfs read fs/read write.c:572
ksys read fs/read write.c:716
do syscall 64 arch/x86/entry/syscall 64.c:84
entry SYSCALL 64 after hwframe arch/x86/entry/entry 64.S:121
Kernel panic - not syncing: KASAN: panic on warn set ...
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux