PT-2026-98696 · Linux · Linux

CVE-2026-98033

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Preserve inner map identity in callback frames
Callback frame constructors initialize map-typed argument registers with mark reg known zero() and then restore map ptr. This clears map uid, which is the only field distinguishing inner maps that share an inner map meta template.
When a timer callback invokes bpf for each map elem() on a second inner map, both the saved first map and the second map value can reach the nested callback as the same template with map uid zero. bpf timer init() then accepts pairing the timer from the second map with the first map.
The runtime records the first map in the timer without taking a reference. Freeing that map does not find the timer stored in the second map, so a later timer callback dereferences the freed map.
Copy map uid from the same caller register as map ptr when constructing for-each, timer/workqueue, and task-work callback arguments. The existing identity check can then reject mismatched inner maps while allowing a callback value to be paired with its actual map.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98033

Affected Products

Linux