PT-2026-98712 · Linux · Linux

CVE-2026-98049

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: zero extend the result of an arena 32-bit cmpxchg
bpf convert ctx accesses() rewrites an atomic on an arena pointer from BPF STX | BPF ATOMIC to BPF STX | BPF PROBE ATOMIC, and it runs before bpf opt subreg zext lo32 rnd hi32().
That pass emits an explicit zero extension for a 32-bit cmpxchg even when bpf jit needs zext() is false. This is done because on some architectures 32-bit cmpxchg requires explicit zero extension for the dst register. E.g. on x86-64 'lock cmpxchg' does not change the %eax if comparison is successful, while BPF semantics declare that each operation on a 32-bit register zero extends it's upper half.
is cmpxchg insn() matches BPF MODE == BPF ATOMIC only, so an arena cmpxchg misses said zero extension adjustment. This patch adjusts is cmpxchg insn() to match BPF PROBE ATOMIC alongside BPF ATOMIC.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98049

Affected Products

Linux