PT-2026-108768 · Linux · Linux

CVE-2026-98382

·

Published

2026-10-09

·

Updated

2026-10-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject dev-bound-only programs on other devices
bpf offload dev match() falls back to comparing offdev pointers after an exact netdev mismatch. Bound-only programs normally have NULL offdevs, so unrelated netdevs compare equal. A bound-only program on an offload-registered netdev can instead inherit a real offdev and match a sibling port. With CAP BPF and CAP NET ADMIN, a caller can use bpf(BPF LINK CREATE) with a different target ifindex to run metadata kfuncs specialized for the bound driver on the target driver's xdp buff. Running a veth-bound program on tun reads beyond tun's bare stack xdp buff as a veth xdp buff.
Oops: general protection fault, probably for non-canonical address KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017] RIP: 0010:veth xdp rx timestamp (drivers/net/veth.c:1673) Call Trace: ... tun build skb (drivers/net/tun.c:1739) tun get user (drivers/net/tun.c:1856) tun chr write iter (drivers/net/tun.c:2091) vfs write (fs/read write.c:595 fs/read write.c:687) ksys write (fs/read write.c:739) do syscall 64 (arch/x86/entry/syscall 64.c:84) entry SYSCALL 64 after hwframe (arch/x86/entry/entry 64.S:121) Kernel panic - not syncing: Fatal exception in interrupt
Restrict non-offloaded programs to exact netdev matches and retain the shared-offdev fallback only for genuinely offloaded multi-port programs.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98382

Affected Products

Linux