PT-2026-98670 · Linux · Linux

CVE-2026-98007

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject non-scalar bpf loop iteration counts
bpf loop() declares its nr loops argument as ARG ANYTHING. Privileged programs may pass pointer values to such arguments, so check func arg() lets a pointer-valued R1 reach the helper-specific checks.
Since commit bb124da69c47 ("bpf: keep track of max number of bpf loop callback iterations"), the verifier marks R1 precise and reads its upper bound to limit callback simulation. Precision backtracking only accepts scalar registers, so passing a pointer instead triggers the "backtracking misuse" verifier warning. Kernels with panic on warn enabled subsequently panic.
Introduce ARG SCALAR for helper arguments that only accept scalar values and use it for bpf loop() nr loops. Generic helper argument validation then rejects pointers before loop inlining and precision processing.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98007

Affected Products

Linux