PT-2026-108768 · Linux · Linux
CVE-2026-98382
·
Published
2026-10-09
·
Updated
2026-10-09
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject dev-bound-only programs on other devices
bpf offload dev match() falls back to comparing offdev pointers after an
exact netdev mismatch. Bound-only programs normally have NULL offdevs, so
unrelated netdevs compare equal. A bound-only program on an
offload-registered netdev can instead inherit a real offdev and match a
sibling port. With CAP BPF and CAP NET ADMIN, a caller can use
bpf(BPF LINK CREATE) with a different target ifindex to run metadata kfuncs
specialized for the bound driver on the target driver's xdp buff. Running a
veth-bound program on tun reads beyond tun's bare stack xdp buff as a
veth xdp buff.
Oops: general protection fault, probably for non-canonical address
KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
RIP: 0010:veth xdp rx timestamp (drivers/net/veth.c:1673)
Call Trace:
...
tun build skb (drivers/net/tun.c:1739)
tun get user (drivers/net/tun.c:1856)
tun chr write iter (drivers/net/tun.c:2091)
vfs write (fs/read write.c:595 fs/read write.c:687)
ksys write (fs/read write.c:739)
do syscall 64 (arch/x86/entry/syscall 64.c:84)
entry SYSCALL 64 after hwframe (arch/x86/entry/entry 64.S:121)
Kernel panic - not syncing: Fatal exception in interrupt
Restrict non-offloaded programs to exact netdev matches and retain the
shared-offdev fallback only for genuinely offloaded multi-port programs.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux