PT-2026-108764 · Linux · Linux

CVE-2026-98378

·

Published

2026-10-09

·

Updated

2026-10-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Skip unsettled links in link iterator
bpf link prime() inserts a link into link idr before anon inode getfile() succeeds and before bpf link settle() publishes the ID in link->id. bpf link by id() treats such an ID-zero link as unsettled, but the link iterator takes a reference without this check.
If anon inode getfile() then fails, the creator removes the ID and frees its still-private link directly. The iterator is left with a dangling reference and its next bpf link put() accesses freed memory.
Treat ID-zero entries as transient in bpf link get curr or next(), just as bpf link by id() does.
BUG: KASAN: slab-use-after-free in bpf link put Write of size 8 by task exp/384 Call Trace: bpf link put kernel/bpf/syscall.c:3372 bpf link seq next kernel/bpf/link iter.c:33 bpf seq read kernel/bpf/bpf iter.c:158 vfs read fs/read write.c:572 ksys read fs/read write.c:716 do syscall 64 arch/x86/entry/syscall 64.c:84 entry SYSCALL 64 after hwframe arch/x86/entry/entry 64.S:121 Kernel panic - not syncing: KASAN: panic on warn set ...
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98378

Affected Products

Linux