PT-2026-98670 · Linux · Linux
CVE-2026-98007
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Reject non-scalar bpf loop iteration counts
bpf loop() declares its nr loops argument as ARG ANYTHING. Privileged
programs may pass pointer values to such arguments, so check func arg()
lets a pointer-valued R1 reach the helper-specific checks.
Since commit bb124da69c47 ("bpf: keep track of max number of bpf loop
callback iterations"), the verifier marks R1 precise and reads its upper
bound to limit callback simulation. Precision backtracking only accepts
scalar registers, so passing a pointer instead triggers the "backtracking
misuse" verifier warning. Kernels with panic on warn enabled subsequently
panic.
Introduce ARG SCALAR for helper arguments that only accept scalar values
and use it for bpf loop() nr loops. Generic helper argument validation then
rejects pointers before loop inlining and precision processing.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux