PT-2026-98696 · Linux · Linux
CVE-2026-98033
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Preserve inner map identity in callback frames
Callback frame constructors initialize map-typed argument registers with
mark reg known zero() and then restore map ptr. This clears map uid,
which is the only field distinguishing inner maps that share an
inner map meta template.
When a timer callback invokes bpf for each map elem() on a second inner
map, both the saved first map and the second map value can reach the nested
callback as the same template with map uid zero. bpf timer init() then
accepts pairing the timer from the second map with the first map.
The runtime records the first map in the timer without taking a reference.
Freeing that map does not find the timer stored in the second map, so a
later timer callback dereferences the freed map.
Copy map uid from the same caller register as map ptr when constructing
for-each, timer/workqueue, and task-work callback arguments. The existing
identity check can then reject mismatched inner maps while allowing a
callback value to be paired with its actual map.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux